{
  "source": {
    "repository": "https://github.com/APIOpsCycles/apiops-cycles-method-data",
    "commit": "4e3a61e4c0427a5b86a79a362e5eed172409434c"
  },
  "locales": [
    "en",
    "fi",
    "fr",
    "de",
    "pt"
  ],
  "defaultLocale": "en",
  "generatedAt": "2026-07-23T20:09:46.873Z",
  "translations": {
    "en": {
      "labels": {
        "stations": "Stations",
        "why_it_matters": "Why this station exists?",
        "outcomes": "Outcomes",
        "how_it_works": "How it works",
        "steps": "Steps",
        "apply_in_work": "This is what success looks like",
        "related_metrolines": "Included in these metrolines",
        "entry_criteria_title": "Starting signals",
        "exit_criteria_title": "Done well when",
        "cycles.title": "Cycle Views",
        "cycles.description": "Audience-specific views over the APIOps Cycles method",
        "cycle.capability-productization-cycle.title": "Capability Productization Cycle",
        "cycle.capability-productization-cycle.description": "A cycle for turning business capabilities into reusable digital capabilities before selecting the implementation style.",
        "cycle.capability-productization-cycle.purpose": "Identify and productize reusable digital capabilities before choosing an API, event, file, stream, data product, AI-enabled service, direct integration, or hybrid implementation style.",
        "cycle.api-productization-cycle.title": "API Productization Cycle",
        "cycle.api-productization-cycle.description": "The API-focused APIOps Cycles journey for productizing, designing, delivering, publishing, and improving APIs.",
        "cycle.api-productization-cycle.purpose": "API-focused method journey for teams that already know the intended implementation style is an API product.",
        "cycle.integration-productization-cycle.title": "Integration Productization Cycle",
        "cycle.integration-productization-cycle.description": "A cycle for productizing reusable integration capabilities before selecting the implementation style.",
        "cycle.integration-productization-cycle.purpose": "Guide reusable integration capability design before choosing an API, event, file, stream, data product, direct integration, or hybrid implementation style.",
        "cycle.station.capability-strategy": "Capability Strategy",
        "cycle.station.consumer-requirements-onboarding": "Consumer Requirements & Onboarding",
        "cycle.station.architecture-platform-decisions": "Architecture & Platform Decisions",
        "cycle.station.solution-interface-design": "Solution & Interface Design",
        "cycle.station.delivery-operations": "Delivery & Operations",
        "cycle.station.quality-readiness-assurance": "Quality & Readiness Assurance",
        "cycle.station.publishing-enablement": "Publishing & Enablement",
        "cycle.station.monitoring-improvement": "Monitoring & Improvement",
        "cycle.station.api-product-strategy": "API Product Strategy",
        "cycle.station.api-consumer-experience": "API Consumer Experience",
        "cycle.station.api-platform-architecture": "API Platform Architecture",
        "cycle.station.api-design": "API Design",
        "cycle.station.api-delivery": "API Delivery",
        "cycle.station.api-audit": "API Audit",
        "cycle.station.api-publishing": "API Publishing",
        "cycle.station.monitoring-and-improving": "API Monitoring & Improvement",
        "cycle.station.integration-capability-strategy": "Integration Capability Strategy",
        "cycle.station.integration-consumer-requirements-onboarding": "Integration Consumer Requirements & Onboarding",
        "cycle.station.integration-architecture-decision": "Integration Architecture & Platform Decisions",
        "cycle.station.integration-solution-design": "Integration Solution Design",
        "cycle.station.integration-delivery-operations": "Integration Delivery & Operations",
        "cycle.station.integration-readiness-assurance": "Integration Readiness Assurance",
        "cycle.station.capability-publishing": "Integration Publishing & Enablement",
        "cycle.station.integration-monitoring-improvement": "Integration Monitoring & Improvement",
        "cycle.capability-productization-cycle.station.api-product-strategy.description": "Frame the business need as a reusable capability with clear value, consumers, ownership, and business goals before selecting the implementation style.",
        "cycle.capability-productization-cycle.station.api-consumer-experience.description": "Capture consumer requirements, onboarding needs, constraints, service expectations, and producer responsibilities.",
        "cycle.capability-productization-cycle.station.api-platform-architecture.description": "Use requirements and constraints to select the implementation style, architecture pattern, and enabling platform capabilities.",
        "cycle.capability-productization-cycle.station.api-design.description": "Design the interface contract and interaction model for the selected implementation style.",
        "cycle.capability-productization-cycle.station.api-delivery.description": "Build, test, deploy, and operate the capability using the selected implementation style and validated interface contract.",
        "cycle.capability-productization-cycle.station.api-audit.description": "Validate the interface contract, controls, documentation, support model, and operational readiness before release.",
        "cycle.capability-productization-cycle.station.api-publishing.description": "Publish the capability so consumers can discover it, evaluate it, request access, complete onboarding, use it, and get support.",
        "cycle.capability-productization-cycle.station.monitoring-and-improving.description": "Monitor capability health, consumer outcomes, reliability, reuse, and improvement opportunities.",
        "cycle.owner.business-owner": "Business owner",
        "cycle.owner.domain-expert": "Domain expert",
        "cycle.owner.capability-owner": "Capability owner",
        "cycle.owner.consumer-representative": "Consumer representative",
        "cycle.owner.enterprise-architect": "Enterprise architect",
        "cycle.owner.platform-owner": "Platform owner",
        "cycle.owner.api-product-owner": "API product owner",
        "cycle.owner.api-platform-owner": "API platform owner",
        "cycle.owner.integration-architect": "Integration architect",
        "cycle.owner.solution-architect": "Solution architect",
        "cycle.api-productization-cycle.station.api-product-strategy.description": "Before building anything, define your API's value, users, and business goals from day one.",
        "cycle.api-productization-cycle.station.api-consumer-experience.description": "Ensure your API is discoverable, understandable, and usable — before and after launch.",
        "cycle.api-productization-cycle.station.api-platform-architecture.description": "Ensure scalability, reuse, and governance across your API and platform components.",
        "cycle.api-productization-cycle.station.api-design.description": "Create API designs that are consistent, reusable, and grounded in business intent and shared standards.",
        "cycle.api-productization-cycle.station.api-delivery.description": "Build, test, and release APIs using modern delivery pipelines and engineering best practices.",
        "cycle.api-productization-cycle.station.api-audit.description": "Validate that APIs meet business, design, and operational standards before release.",
        "cycle.api-productization-cycle.station.api-publishing.description": "Expose APIs securely and clearly to the right audience with the right documentation and processes.",
        "cycle.api-productization-cycle.station.monitoring-and-improving.description": "Use metrics and feedback to track API performance and drive continuous improvement.",
        "cycle.integration-productization-cycle.station.api-product-strategy.description": "Frame the reusable integration capability, business need, ownership, and expected reuse before selecting the implementation style.",
        "cycle.integration-productization-cycle.station.api-consumer-experience.description": "Capture integration consumers, provider responsibilities, onboarding needs, service expectations, and operational constraints.",
        "cycle.integration-productization-cycle.station.api-platform-architecture.description": "Select the integration architecture, implementation style, and platform capabilities, taking account of constraints and the governance model.",
        "cycle.integration-productization-cycle.station.api-design.description": "Design the interface contract, schemas, payloads, and interaction patterns for the selected integration style.",
        "cycle.integration-productization-cycle.station.api-delivery.description": "Build, test, automate, deploy, and operate the integration capability using its selected implementation style and validated interface contract.",
        "cycle.integration-productization-cycle.station.api-audit.description": "Assure integration readiness, governance, quality, security, compliance, and operational evidence before release.",
        "cycle.integration-productization-cycle.station.api-publishing.description": "Publish the integration capability so teams can discover it, evaluate it, request access, complete onboarding, reuse it, and get support.",
        "cycle.integration-productization-cycle.station.monitoring-and-improving.description": "Monitor integration reliability, reuse, incidents, performance, consumer outcomes, and improvement needs.",
        "cycle.automation-cycle.title": "Automation Cycle",
        "cycle.automation-cycle.description": "A cycle for identifying, designing, delivering, enabling, and improving automation opportunities.",
        "cycle.automation-cycle.purpose": "Productize automation opportunities into governed workflows with clear users, platforms, controls, delivery paths, enablement, and monitoring.",
        "cycle.audience.automation-owners": "Automation owners",
        "cycle.audience.process-owners": "Process owners",
        "cycle.audience.automation-teams": "Automation teams",
        "cycle.station.automation-opportunity-strategy": "Automation Opportunity Strategy",
        "cycle.station.process-user-requirements": "Process & User Requirements",
        "cycle.station.automation-platform-decision": "Automation Platform Decision",
        "cycle.station.automation-workflow-design": "Automation Workflow Design",
        "cycle.station.automation-delivery": "Automation Delivery & Operations",
        "cycle.station.automation-readiness-review": "Automation Readiness Review",
        "cycle.station.automation-enablement": "Automation Rollout & Enablement",
        "cycle.station.automation-monitoring-improvement": "Automation Monitoring & Improvement",
        "cycle.automation-cycle.station.api-product-strategy.description": "Identify and prioritize automation opportunities by value, feasibility, risk, ownership, and expected process impact.",
        "cycle.automation-cycle.station.api-consumer-experience.description": "Capture process users, roles, handoffs, exceptions, constraints, and service expectations before designing the automation.",
        "cycle.automation-cycle.station.api-platform-architecture.description": "Choose the automation platform, runtime, integration approach, governance controls, and operating constraints.",
        "cycle.automation-cycle.station.api-design.description": "Design the automation workflow, triggers, decision points, integrations, data handling, relevant interface contracts, and exception paths.",
        "cycle.automation-cycle.station.api-delivery.description": "Build, test, deploy, document, and operate the automation using clear ownership, controls, and rollback paths.",
        "cycle.automation-cycle.station.api-audit.description": "Review automation readiness, quality, risk, compliance, human oversight, evidence, and release criteria.",
        "cycle.automation-cycle.station.api-publishing.description": "Roll out the automation with discovery, onboarding, operating instructions, support paths, and change communication for users and operators.",
        "cycle.automation-cycle.station.monitoring-and-improving.description": "Monitor automation performance, exceptions, reliability, user outcomes, operational impact, and improvement opportunities.",
        "group.core-stations.title": "Capability Lifecycle Core Stations",
        "group.core-stations.description": "The core stations of the method, where teams can learn how to design, deliver, govern, and improve reusable capabilities across APIs, events, files, streams, data products, and other integration styles.",
        "station.api-product-strategy.title": "Strategy",
        "station.api-product-strategy.description": "Frame the business need as a reusable capability before choosing the implementation style.",
        "station.api-product-strategy.why_it_matters": "Integration and API work often jumps too quickly to a technical pattern. This station keeps the team focused on the business journey, domain meaning, value, reuse potential, ownership, and viability before selecting APIs, events, files, streams, data products, or direct integration.",
        "station.api-product-strategy.apply_in_work": "Use shared journey, domain, value proposition, and business model canvases to gather technology-agnostic requirements and decide whether the capability should be reusable.",
        "station.api-product-strategy.outcomes": "A technology-agnostic capability opportunity statement",
        "station.api-product-strategy.outcomes.1": "Shared understanding of consumers, producers, domain concepts, and reuse potential",
        "station.api-product-strategy.outcomes.2": "A capability value proposition and business model before architecture selection",
        "station.api-product-strategy.how_it_works": "Map the customer or partner journey that creates the capability need and reveals tasks, pains, gains, inputs, outputs, and decision points.",
        "station.api-product-strategy.how_it_works.1": "Define the core entities, attributes, relationships, ownership, and business rules that the capability must respect.",
        "station.api-product-strategy.how_it_works.2": "Use the Capability Value Proposition Canvas to capture consumer tasks, gains, pains, and reusable capability features without naming the delivery technology too early.",
        "station.api-product-strategy.how_it_works.3": "Use the Capability Business Model Canvas to clarify ownership, partners, channels, costs, benefits, support, and lifecycle expectations for the reusable capability.",
        "station.api-consumer-experience.title": "Consumer Requirements & Onboarding",
        "station.api-consumer-experience.description": "Capture consumer onboarding, standards, non-functional requirements, service expectations, constraints, security needs, allowed protocols, data freshness, SLAs, observability, recovery, adoption requirements, and producer responsibilities.",
        "station.api-consumer-experience.why_it_matters": "The right architecture depends on consumer goals, onboarding expectations, service levels, data quality needs, change tolerance, observability, support, and producer constraints.",
        "station.api-consumer-experience.how_it_works": "Use the Consumer Experience Requirements Canvas to capture consumer goals, availability, freshness, volume, performance, data quality, security, onboarding, change, observability, and recovery expectations.",
        "station.api-consumer-experience.how_it_works.1": "Use onboarding guidance to describe how consumers will find, request, test, get approved for, and start using the capability.",
        "station.api-consumer-experience.how_it_works.2": "Use the resulting journey and requirements to improve onboarding, documentation, support, and feedback loops for capability consumers.",
        "station.api-consumer-experience.apply_in_work": "Use consumer experience and onboarding guidance to make expectations explicit for both consumers and producers.",
        "station.api-consumer-experience.outcomes": "Documented consumer requirements and onboarding expectations",
        "station.api-consumer-experience.outcomes.1": "Clear producer responsibilities and support expectations",
        "station.api-consumer-experience.outcomes.2": "Architecture-relevant constraints ready for decision making",
        "station.api-consumer-experience.outcomes.3": "Improved adoption through consumer empathy, standards, and producer clarity",
        "station.api-platform-architecture.title": "Architecture & Platform Decisions",
        "station.api-platform-architecture.description": "Use requirements and constraints to decide the right architecture pattern and enabling platform capabilities.",
        "station.api-platform-architecture.why_it_matters": "Architecture choices should follow from evidence about business impact, locations, trust boundaries, capacity, latency, data ownership, consistency, operability, security, privacy, governance, and cost.",
        "station.api-platform-architecture.apply_in_work": "Compare viable architecture styles against the gathered requirements and document the selected pattern and rationale.",
        "station.api-platform-architecture.outcomes": "A justified architecture choice",
        "station.api-platform-architecture.outcomes.1": "Documented risks, locations, capacity, security, privacy, and operability constraints",
        "station.api-platform-architecture.outcomes.2": "Clear rationale for API, event, file, stream, data product, direct integration, or hybrid implementation style",
        "station.api-platform-architecture.how_it_works": "Use the Business Impact Canvas to identify availability, security, and data risks that influence architecture options.",
        "station.api-platform-architecture.how_it_works.1": "Use the Locations Canvas to capture geopolitical, regulatory, network, residency, and trust-boundary constraints.",
        "station.api-platform-architecture.how_it_works.2": "Use the Capacity Canvas to capture current and future volumes, peaks, latency, caching, rate limiting, and scaling expectations.",
        "station.api-platform-architecture.how_it_works.3": "Use metrics and analytics guidance to define how the chosen capability will be monitored and improved.",
        "station.api-design.title": "Solution & Interface Design",
        "station.api-design.description": "Design the interface contract and interaction model after the architecture choice is justified.",
        "station.api-design.why_it_matters": "Once the architecture pattern is known, the design must turn capability requirements into clear interface contracts, interactions, schemas, data rules, lifecycle expectations, and consumer obligations.",
        "station.api-design.apply_in_work": "Select the design resources that fit the chosen implementation style and document the interface contract before implementation.",
        "station.api-design.outcomes": "A validated interface contract for the selected implementation style",
        "station.api-design.outcomes.1": "Consistent interaction, data, event, file, workflow, or API contract decisions",
        "station.api-design.outcomes.2": "Design traceability back to capability and consumer requirements",
        "station.api-design.outcomes.3": "Designs aligned with domain models and interaction patterns",
        "station.api-design.how_it_works": "Reuse the Domain Canvas to confirm business objects, terms, rules, and ownership before contract design.",
        "station.api-design.how_it_works.1": "Use the Interaction Canvas to describe how consumers, systems, or users interact with the capability.",
        "station.api-design.how_it_works.2": "Use REST design resources when the selected interface is a REST API.",
        "station.api-design.how_it_works.3": "Use Event Canvas resources when the selected interface is event-driven.",
        "station.api-design.how_it_works.4": "Use GraphQL design resources when the selected interface is GraphQL.",
        "station.api-design.how_it_works.5": "Use the design principles and style guidance to align design decisions with shared rules and enable consistent audit validation.",
        "station.api-design.how_it_works.6": "Apply contract-first or design-first approaches to capture and validate the interface contract before implementation.",
        "station.api-design.how_it_works.7": "Use the audit checklist to ensure the design meets functional and non-functional requirements, including security, performance, and compliance.",
        "station.api-delivery.title": "Delivery & Operations",
        "station.api-delivery.description": "Deliver the selected implementation style with appropriate engineering, testing, security, automation, and operational practices.",
        "station.api-delivery.why_it_matters": "A reusable capability needs reliable delivery and operations regardless of whether it becomes an API, event stream, file exchange, data product, or direct integration.",
        "station.api-delivery.apply_in_work": "Apply delivery, testing, CI/CD, operations, and security guidance to the chosen implementation style.",
        "station.api-delivery.outcomes": "A delivered capability aligned with the validated interface contract",
        "station.api-delivery.outcomes.1": "Automated testing, deployment, and environment controls",
        "station.api-delivery.outcomes.2": "Security, operations, and quality practices appropriate to the chosen pattern",
        "station.api-delivery.outcomes.3": "Traceable delivery and release controls",
        "station.api-delivery.how_it_works": "Use development best practices to implement the validated interface contract with established frameworks, libraries, and team standards.",
        "station.api-delivery.how_it_works.1": "Build the implementation from the validated interface contract using established frameworks, libraries, and team standards.",
        "station.api-delivery.how_it_works.2": "Use testing guidance to verify functionality, data quality, compatibility, security, performance, resilience, and recovery expectations.",
        "station.api-delivery.how_it_works.3": "Use CI/CD guidance to automate build, test, deployment, configuration, and traceability.",
        "station.api-delivery.how_it_works.4": "Use security guidance to protect data, access, credentials, and platform boundaries.",
        "station.api-delivery.how_it_works.5": "Use the audit checklist to ensure the solution meets functional and non-functional requirements, including security, performance, and compliance.",
        "station.api-audit.title": "Quality & Readiness Assurance",
        "station.api-audit.description": "Audit the capability interface contract, controls, support model, observability, documentation, and lifecycle readiness before release.",
        "station.api-audit.why_it_matters": "Reusable capabilities create operational, data, security, privacy, compliance, and consumer-impact risks. Readiness checks reduce surprises before release or production use.",
        "station.api-audit.apply_in_work": "Use audit and compliance resources to verify that the capability is ready for controlled release and reuse.",
        "station.api-audit.outcomes": "Documented readiness for release and reuse",
        "station.api-audit.outcomes.1": "Known gaps and mitigations before release",
        "station.api-audit.outcomes.2": "Evidence for governance, compliance, support, and operational approval",
        "station.api-audit.outcomes.3": "Reduced risk of issues in production",
        "station.api-audit.how_it_works": "Use the audit checklist as a reusable quality checklist for interface contract, documentation, security, performance, and compliance readiness.",
        "station.api-audit.how_it_works.1": "Use checklists, linters, and testing tools to verify consistency and conformance with standards.",
        "station.api-audit.how_it_works.2": "Collaborate with governance teams and domain experts to ensure the capability is ready for production.",
        "station.api-publishing.title": "Publishing & Enablement",
        "station.api-publishing.description": "Publish reusable capability information so consumers can discover, request, onboard, use, and get support.",
        "station.api-publishing.why_it_matters": "Reusable capabilities only create value when consumers can find them, understand their interface contract and service expectations, request access, and know who owns support and lifecycle decisions.",
        "station.api-publishing.apply_in_work": "Publish ownership, documentation, onboarding, support contacts, service expectations, lifecycle status, and access request paths.",
        "station.api-publishing.outcomes": "A discoverable reusable capability",
        "station.api-publishing.outcomes.1": "Clear onboarding, access, support, and service expectations",
        "station.api-publishing.outcomes.2": "Lifecycle and ownership information available to consumers and governance teams",
        "station.api-publishing.outcomes.3": "Consumers enabled to use and reuse the capability",
        "station.api-publishing.how_it_works": "Publish capability information to the appropriate catalogs, portals, gateways, or environments to support reuse by multiple consumers.",
        "station.api-publishing.how_it_works.1": "Document how consumers find and use the capability, including onboarding processes and registration.",
        "station.api-publishing.how_it_works.2": "Ensure security models, access configuration, and legal terms are clear and accessible to consumers.",
        "station.monitoring-and-improving.title": "Monitoring & Improvement",
        "station.monitoring-and-improving.description": "Monitor usage, reliability, data quality, consumer outcomes, operational cost, and reuse opportunities after release.",
        "station.monitoring-and-improving.why_it_matters": "Capabilities need continuous feedback to stay reliable, valuable, cost-effective, and reusable as consumers, systems, data, and platforms change.",
        "station.monitoring-and-improving.apply_in_work": "Use metrics, analytics, and engagement practices to improve the capability over time.",
        "station.monitoring-and-improving.outcomes": "Measured capability health and value",
        "station.monitoring-and-improving.outcomes.1": "Improvement backlog informed by operational and consumer feedback",
        "station.monitoring-and-improving.outcomes.2": "Reuse, reliability, data quality, and cost signals available to owners",
        "station.monitoring-and-improving.outcomes.3": "Continuous improvement aligned with consumer needs",
        "station.monitoring-and-improving.how_it_works": "Use metrics and analytics guidance to define capability usage, reliability, data quality, cost, adoption, and consumer-value measures.",
        "station.monitoring-and-improving.how_it_works.1": "Analyze usage metrics and incorporate consumer feedback into capability iterations.",
        "station.monitoring-and-improving.how_it_works.2": "Establish a habit of reviewing metrics and planning continuous improvement activities.",
        "group.sub-stations.title": "Supporting Stations",
        "group.sub-stations.description": "Supporting stations provide reusable practices, decision points and resources that can be included in different APIOps Cycles routes, including capability, API, integration, data and AI-enabled productization.",
        "station.user-experience.title": "User Experience - Design APIs with the User in Mind",
        "station.user-experience.description": "Ensure APIs are designed with the end user in mind, providing a seamless and intuitive experience.",
        "station.user-experience.why_it_matters": "APIs are not just technical products; they are user-facing products. A poor user experience can lead to low adoption and frustration. This station helps teams design APIs that are user-friendly and meet consumer needs.",
        "station.user-experience.apply_in_work": "Provide user experience guidelines, templates, and tools for API design. Ensure teams follow user-centered design practices and incorporate user feedback into API iterations.",
        "station.user-experience.outcomes": "APIs designed with user needs in mind",
        "station.user-experience.outcomes.1": "Intuitive and consistent user interfaces",
        "station.user-experience.outcomes.2": "User feedback incorporated into API design",
        "station.user-experience.outcomes.3": "Improved user satisfaction and adoption",
        "station.user-experience.how_it_works": "Use user personas to understand the needs and expectations of end-users",
        "station.user-experience.how_it_works.1": "Conduct user research to gather insights on how consumers interact with the ecosystem services or your API consuming applications.",
        "station.user-experience.how_it_works.2": "Document the user experience requirements so that they can be used in API design, ensuring they are intuitive and easy to use.",
        "station.market-insights.title": "Market Insights - Understand the API Landscape",
        "station.market-insights.description": "Analyze market trends, competitor APIs, and industry standards to inform API strategy.",
        "station.market-insights.why_it_matters": "Understanding the market landscape helps teams identify opportunities, avoid pitfalls, and align their APIs with industry standards. This station provides tools to analyze market trends and competitor offerings.",
        "station.market-insights.apply_in_work": "Provide market research tools, competitor analysis templates, and industry standards resources. Ensure teams stay informed about market trends and incorporate insights into API strategy.",
        "station.market-insights.outcomes": "Market trends and competitor APIs analyzed",
        "station.market-insights.outcomes.1": "Industry standards and best practices identified",
        "station.market-insights.outcomes.2": "API strategy aligned with market needs",
        "station.market-insights.outcomes.3": "Informed decision-making based on market insights",
        "station.market-insights.how_it_works": "Conduct market research to identify trends, opportunities, and threats in the API landscape.",
        "station.market-insights.how_it_works.1": "Analyze competitor APIs to understand their strengths, weaknesses, and unique selling points.",
        "station.market-insights.how_it_works.2": "Identify industry standards and best practices to ensure APIs are competitive and compliant.",
        "station.business-goals.title": "Business Goals - Align APIs with Business Objectives",
        "station.business-goals.description": "Ensure APIs are aligned with business objectives and contribute to overall organizational goals.",
        "station.business-goals.why_it_matters": "APIs should not be built in isolation; they must support and drive business objectives. This station helps teams align their APIs with strategic goals, ensuring they deliver real business value.",
        "station.business-goals.apply_in_work": "Provide business alignment frameworks, templates, and tools for defining API business value. Ensure teams regularly review and align APIs with changing business objectives.",
        "station.business-goals.outcomes": "APIs aligned with business objectives",
        "station.business-goals.outcomes.1": "Clear business value defined for each API",
        "station.business-goals.outcomes.2": "Stakeholder buy-in and support for API initiatives",
        "station.business-goals.outcomes.3": "APIs contribute to organizational success",
        "station.business-goals.how_it_works": "Define business objectives and how APIs can support them using **the Business Model Canvas**. If your business is to provide APIs, go through *the API Product Strategy station* and fill in **the API Business Model Canvas.**",
        "station.business-goals.how_it_works.1": "Identify key performance indicators (KPIs) to measure API success against business goals.",
        "station.business-goals.how_it_works.2": "Engage stakeholders to ensure alignment and support for API initiatives.",
        "station.competitive-analysis.title": "Competitive Analysis - Stay Ahead in the API Market",
        "station.competitive-analysis.description": "Analyze competitors' APIs to identify strengths, weaknesses, and opportunities for differentiation.",
        "station.competitive-analysis.why_it_matters": "Understanding the competitive landscape helps teams identify gaps, opportunities, and areas for improvement in their APIs. This station provides tools to analyze competitors and inform API strategy.",
        "station.competitive-analysis.apply_in_work": "Provide competitive analysis tools, templates, and resources. Ensure teams regularly analyze competitors and incorporate insights into API strategy and design.",
        "station.competitive-analysis.outcomes": "Competitor APIs analyzed for strengths and weaknesses",
        "station.competitive-analysis.outcomes.1": "Opportunities for differentiation identified",
        "station.competitive-analysis.outcomes.2": "API strategy informed by competitive insights",
        "station.competitive-analysis.outcomes.3": "Increased competitiveness in the API market",
        "station.competitive-analysis.how_it_works": "Conduct a competitive analysis to identify key competitors, their API offerings, and their strengths and weaknesses.",
        "station.competitive-analysis.how_it_works.1": "Identify gaps in the market that your APIs can fill, based on competitor offerings.",
        "station.competitive-analysis.how_it_works.2": "Develop a differentiation strategy that highlights unique features and benefits of your APIs.",
        "station.ecosystem-vision.title": "Ecosystem Vision - Build APIs for a Thriving Ecosystem",
        "station.ecosystem-vision.description": "Create a vision for how your APIs fit into a larger ecosystem, enabling collaboration and innovation.",
        "station.ecosystem-vision.why_it_matters": "APIs are not standalone products; they are part of a larger ecosystem. This station helps teams define how their APIs interact with other systems, platforms, and services to create a thriving ecosystem that fosters collaboration and innovation.",
        "station.ecosystem-vision.apply_in_work": "Provide ecosystem vision frameworks, partner engagement strategies, and integration guidelines. Ensure teams design APIs with the ecosystem in mind and foster collaboration among partners.",
        "station.ecosystem-vision.outcomes": "Clear ecosystem vision defined for APIs",
        "station.ecosystem-vision.outcomes.1": "APIs designed to enable collaboration and integration",
        "station.ecosystem-vision.outcomes.2": "Ecosystem partners identified and engaged",
        "station.ecosystem-vision.outcomes.3": "APIs contribute to a vibrant ecosystem",
        "station.ecosystem-vision.how_it_works": "Define the ecosystem vision for your APIs, including how they will interact with other systems and platforms.",
        "station.ecosystem-vision.how_it_works.1": "Identify key ecosystem partners and stakeholders who will benefit from or contribute to the ecosystem.",
        "station.ecosystem-vision.how_it_works.2": "Design APIs to enable seamless integration and collaboration within the ecosystem.",
        "station.scalable-infrastructure.title": "Scalable Infrastructure - Build APIs on a Solid Foundation",
        "station.scalable-infrastructure.description": "Ensure your API infrastructure can scale to meet growing demand and support high availability.",
        "station.scalable-infrastructure.why_it_matters": "APIs must be built on a robust infrastructure that can handle increasing traffic and ensure high availability. This station provides guidelines for designing and implementing scalable infrastructure that supports API growth and performance.",
        "station.scalable-infrastructure.apply_in_work": "Provide infrastructure design guidelines, cloud-native patterns, and monitoring tools. Ensure teams implement scalable infrastructure that can adapt to changing demands and support API performance.",
        "station.scalable-infrastructure.outcomes": "Scalable and resilient API infrastructure",
        "station.scalable-infrastructure.outcomes.1": "High availability and performance under load",
        "station.scalable-infrastructure.outcomes.2": "Infrastructure designed for future growth",
        "station.scalable-infrastructure.outcomes.3": "Reduced downtime and improved user experience",
        "station.scalable-infrastructure.how_it_works": "Design API infrastructure to be scalable and resilient, using cloud-native patterns and technologies.",
        "station.scalable-infrastructure.how_it_works.1": "Implement load balancing, caching, and other techniques to ensure high availability and performance. Collect infrastructure requirements from API teams using Capacity Canvas",
        "station.scalable-infrastructure.how_it_works.2": "Monitor infrastructure performance and capacity to ensure it can handle growing demand.",
        "station.legal-and-compliance.title": "Legal and Compliance - Ensure APIs Meet Regulatory Standards",
        "station.legal-and-compliance.description": "Ensure APIs comply with legal and regulatory requirements, protecting your organization and users.",
        "station.legal-and-compliance.why_it_matters": "APIs must adhere to legal and regulatory standards to protect your organization and users. This station provides tools and guidelines for ensuring APIs meet compliance requirements, reducing legal risks and ensuring data protection.",
        "station.legal-and-compliance.apply_in_work": "Provide legal and compliance frameworks, checklists, and tools for ensuring API compliance. Ensure teams understand and implement legal requirements in API design, development, and publishing.",
        "station.legal-and-compliance.outcomes": "APIs compliant with legal and regulatory standards",
        "station.legal-and-compliance.outcomes.1": "Data protection and privacy requirements met",
        "station.legal-and-compliance.outcomes.2": "Legal risks identified and mitigated",
        "station.legal-and-compliance.outcomes.3": "Clear documentation of compliance measures",
        "station.legal-and-compliance.how_it_works": "Identify legal and regulatory requirements that apply to your APIs, such as data protection, privacy, and security standards.",
        "station.legal-and-compliance.how_it_works.1": "Implement measures to ensure APIs comply with these requirements, including data encryption, access controls, and audit trails.",
        "station.legal-and-compliance.how_it_works.2": "Document compliance measures and ensure they are communicated to stakeholders and consumers.",
        "station.security-and-privacy.title": "Security and Privacy - Protect Your APIs and Users",
        "station.security-and-privacy.description": "Implement security and privacy measures to protect APIs and user data from threats and breaches.",
        "station.security-and-privacy.why_it_matters": "APIs are vulnerable to security threats and data breaches. This station provides guidelines for implementing security and privacy measures that protect APIs and user data, ensuring trust and compliance.",
        "station.security-and-privacy.apply_in_work": "Provide security frameworks, tools, and best practices for API security and privacy. Ensure teams implement security measures throughout the API lifecycle, from design to publishing and monitoring.",
        "station.security-and-privacy.outcomes": "APIs secured against threats and vulnerabilities",
        "station.security-and-privacy.outcomes.1": "User data protected through privacy measures",
        "station.security-and-privacy.outcomes.2": "Security best practices implemented in API design and development",
        "station.security-and-privacy.outcomes.3": "Compliance with security standards and regulations",
        "station.security-and-privacy.how_it_works": "Implement security measures such as authentication, authorization, encryption, and rate limiting to protect APIs from threats.",
        "station.security-and-privacy.how_it_works.1": "Ensure user data privacy by implementing data protection measures, such as anonymization and access controls.",
        "station.security-and-privacy.how_it_works.2": "Conduct regular security audits and vulnerability assessments to identify and mitigate risks.",
        "station.design-standards.title": "Design Standards - Ensure Consistent and High-Quality API Design",
        "station.design-standards.description": "Establish design standards and guidelines to ensure consistent and high-quality API design across the organization.",
        "station.design-standards.why_it_matters": "Consistent and high-quality API design is essential for usability, maintainability, and scalability. This station provides design standards and guidelines that help teams create APIs that are easy to use, understand, and maintain.",
        "station.design-standards.apply_in_work": "Provide design standards documentation, reusable components, and design review processes. Ensure teams follow design standards and conduct regular reviews to maintain high-quality API design.",
        "station.design-standards.outcomes": "Consistent API design across the organization",
        "station.design-standards.outcomes.1": "High-quality APIs that meet user needs",
        "station.design-standards.outcomes.2": "Reusable design patterns and components",
        "station.design-standards.outcomes.3": "Reduced design inconsistencies and technical debt",
        "station.design-standards.how_it_works": "Define design standards and guidelines for API design, including naming conventions, response formats, and error handling.",
        "station.design-standards.how_it_works.1": "Create reusable design patterns and components that teams can leverage to ensure consistency and quality.",
        "station.design-standards.how_it_works.2": "Conduct design reviews and audits to ensure adherence to design standards and identify areas for improvement.",
        "station.vendor-management.title": "Vendor Management - Manage Third-Party API Integrations",
        "station.vendor-management.description": "Effectively manage third-party API vendors and integrations to ensure reliability and compliance.",
        "station.vendor-management.why_it_matters": "Third-party APIs can introduce risks and dependencies that impact your API ecosystem. This station provides guidelines for managing vendor relationships, ensuring reliability, compliance, and alignment with your API strategy.",
        "station.vendor-management.apply_in_work": "Provide vendor management frameworks, evaluation criteria, and monitoring tools. Ensure teams effectively manage third-party API vendors, ensuring reliability, compliance, and alignment with organizational standards.",
        "station.vendor-management.outcomes": "Effective vendor management processes established",
        "station.vendor-management.outcomes.1": "Third-party APIs integrated reliably and securely",
        "station.vendor-management.outcomes.2": "Vendor compliance with organizational standards",
        "station.vendor-management.outcomes.3": "Reduced risks associated with third-party dependencies",
        "station.vendor-management.how_it_works": "Establish vendor management processes to evaluate, onboard, and monitor third-party API vendors.",
        "station.vendor-management.how_it_works.1": "Define criteria for evaluating vendor APIs, including reliability, security, and compliance.",
        "station.vendor-management.how_it_works.2": "Monitor vendor performance and compliance with service level agreements (SLAs) and organizational standards.",
        "station.contract-design.title": "Contract Design - Define Clear API Contracts",
        "station.contract-design.description": "Create clear and well-defined API contracts that outline expectations, responsibilities, and usage guidelines.",
        "station.contract-design.why_it_matters": "API contracts are essential for ensuring clarity and alignment between API providers and consumers. This station provides guidelines for designing API contracts that are clear, comprehensive, and easy to understand.",
        "station.contract-design.apply_in_work": "Provide contract design templates, standardized formats, and review processes. Ensure teams create clear and well-defined API contracts that outline expectations, responsibilities, and usage guidelines.",
        "station.contract-design.outcomes": "Clear API contracts defined for each API",
        "station.contract-design.outcomes.1": "Expectations and responsibilities outlined for API providers and consumers",
        "station.contract-design.outcomes.2": "Usage guidelines and best practices documented",
        "station.contract-design.outcomes.3": "Reduced misunderstandings and disputes over API usage",
        "station.contract-design.how_it_works": "Define API contracts that outline the expectations, responsibilities, and usage guidelines for each API.",
        "station.contract-design.how_it_works.1": "Use standardized formats (e.g., OpenAPI, AsyncAPI) to create machine-readable API contracts that are easy to share and validate.",
        "station.contract-design.how_it_works.2": "Ensure API contracts are reviewed and approved by stakeholders to ensure alignment and clarity.",
        "station.development.title": "Development - Build APIs with Best Practices",
        "station.development.description": "Implement APIs using best practices and frameworks to ensure quality, maintainability, and scalability.",
        "station.development.why_it_matters": "API development is a critical phase that determines the quality and reliability of the API. This station provides best practices and frameworks for API development, ensuring APIs are built to high standards and can be maintained and scaled effectively.",
        "station.development.apply_in_work": "Provide development frameworks, libraries, and coding standards for API implementation. Ensure teams follow best practices and conduct code reviews to maintain high-quality API development.",
        "station.development.outcomes": "APIs developed using best practices and frameworks",
        "station.development.outcomes.1": "High-quality, maintainable, and scalable APIs",
        "station.development.outcomes.2": "Consistent coding standards and practices followed",
        "station.development.outcomes.3": "Reduced development time and technical debt",
        "station.development.how_it_works": "Use established frameworks and libraries to implement APIs, ensuring they are reusable and maintainable.",
        "station.development.how_it_works.1": "Apply contract-first or design-first approaches to ensure API contracts are validated before implementation.",
        "station.development.how_it_works.2": "Follow coding standards and best practices to ensure consistent and high-quality API development.",
        "station.ci-cd.title": "CI/CD - Automate API Delivery",
        "station.ci-cd.description": "Implement continuous integration and continuous delivery (CI/CD) pipelines to automate API delivery and ensure consistent quality.",
        "station.ci-cd.why_it_matters": "CI/CD is essential for ensuring that APIs are delivered quickly, reliably, and with high quality. This station provides guidelines for implementing CI/CD pipelines that automate the build, test, and deployment processes for APIs.",
        "station.ci-cd.apply_in_work": "Provide CI/CD frameworks, tools, and best practices for API delivery. Ensure teams implement automated pipelines that support continuous integration, testing, and deployment of APIs.",
        "station.ci-cd.outcomes": "Automated CI/CD pipelines established for API delivery",
        "station.ci-cd.outcomes.1": "Consistent quality and traceability in API delivery",
        "station.ci-cd.outcomes.2": "Faster iterations and reduced time to market",
        "station.ci-cd.outcomes.3": "Improved collaboration and feedback loops in API development",
        "station.ci-cd.how_it_works": "Use CI/CD pipelines to automate build, test, and deployment processes, ensuring consistent quality and traceability.",
        "station.ci-cd.how_it_works.1": "Integrate functional and non-functional testing into the CI/CD pipeline to ensure APIs meet quality standards.",
        "station.ci-cd.how_it_works.2": "Implement automated security checks and compliance validations in the CI/CD pipeline to ensure APIs are secure and compliant.",
        "station.test-automation.title": "Test Automation - Ensure API Quality",
        "station.test-automation.description": "Implement automated testing practices to ensure API quality, reliability, and performance.",
        "station.test-automation.why_it_matters": "Automated testing is crucial for ensuring that APIs function correctly and meet quality standards. This station provides guidelines for implementing automated testing practices that cover functional, security, and performance testing for APIs.",
        "station.test-automation.apply_in_work": "Provide test automation frameworks, tools, and best practices for API testing. Ensure teams implement automated tests that cover functional, security, and performance aspects of APIs.",
        "station.test-automation.outcomes": "Automated testing practices implemented for APIs",
        "station.test-automation.outcomes.1": "Functional, security, and performance tests automated",
        "station.test-automation.outcomes.2": "Reduced manual testing effort and increased test coverage",
        "station.test-automation.outcomes.3": "Improved API reliability and quality",
        "station.test-automation.how_it_works": "Use automated testing tools to validate API functionality, security, and performance.",
        "station.test-automation.how_it_works.1": "Implement test automation frameworks that support contract testing, integration testing, and end-to-end testing.",
        "station.test-automation.how_it_works.2": "Integrate automated tests into the CI/CD pipeline to ensure continuous validation of API quality.",
        "station.release-management.title": "Release Management - Manage API Releases Effectively",
        "station.release-management.description": "Implement release management practices to ensure smooth and controlled API releases.",
        "station.release-management.why_it_matters": "Effective release management is essential for ensuring that API releases are smooth, controlled, and aligned with business needs. This station provides guidelines for managing API releases, including versioning, deployment strategies, and rollback procedures.",
        "station.release-management.apply_in_work": "Provide release management frameworks, versioning guidelines, and deployment strategies. Ensure teams follow best practices for managing API releases, including versioning, deployment, and rollback procedures.",
        "station.release-management.outcomes": "Controlled and smooth API releases",
        "station.release-management.outcomes.1": "Versioning and deployment strategies defined",
        "station.release-management.outcomes.2": "Rollback procedures established for API releases",
        "station.release-management.outcomes.3": "Reduced risks associated with API changes",
        "station.release-management.how_it_works": "Define versioning strategies for APIs to manage changes and ensure backward compatibility.",
        "station.release-management.how_it_works.1": "Implement deployment strategies (e.g., blue-green deployments, canary releases) to minimize risks during API releases.",
        "station.release-management.how_it_works.2": "Establish rollback procedures to quickly revert changes in case of issues during API releases.",
        "station.service-agreements.title": "Service Agreements - Define API Service Levels",
        "station.service-agreements.description": "Establish service agreements that define expectations, service levels, and responsibilities for API providers and consumers.",
        "station.service-agreements.why_it_matters": "Service agreements are essential for ensuring clarity and alignment between API providers and consumers. This station provides guidelines for creating service agreements that outline expectations, service levels, and responsibilities, reducing misunderstandings and disputes.",
        "station.service-agreements.apply_in_work": "Provide service agreement templates, standardized formats, and review processes. Ensure teams create clear and well-defined service agreements that outline expectations, service levels, and responsibilities for API providers and consumers.",
        "station.service-agreements.outcomes": "Clear service agreements defined for each API",
        "station.service-agreements.outcomes.1": "Expectations and service levels outlined for API providers and consumers",
        "station.service-agreements.outcomes.2": "Responsibilities and support processes documented",
        "station.service-agreements.outcomes.3": "Improved communication and collaboration between API teams",
        "station.service-agreements.how_it_works": "Define service agreements that outline the expectations, service levels, and responsibilities for each API.",
        "station.service-agreements.how_it_works.1": "Use standardized formats to create machine-readable service agreements that are easy to share and validate.",
        "station.service-agreements.how_it_works.2": "Ensure service agreements are reviewed and approved by stakeholders to ensure alignment and clarity.",
        "station.api-consumer-adoption.title": "Consumer Adoption",
        "station.api-consumer-adoption.description": "Implement strategies to drive consumer adoption and engagement so reusable capabilities are used effectively.",
        "station.api-consumer-adoption.why_it_matters": "Driving consumer adoption is crucial for realizing the value of reusable capabilities. This station provides strategies and best practices for engaging consumers, helping them understand how to use capabilities effectively and derive value from them.",
        "station.api-consumer-adoption.apply_in_work": "Provide onboarding resources, educational materials, and engagement strategies for consumers. Ensure teams implement adoption practices that improve engagement, satisfaction, and reuse.",
        "station.api-consumer-adoption.outcomes": "Consumer adoption strategies implemented",
        "station.api-consumer-adoption.outcomes.1": "Increased usage and engagement",
        "station.api-consumer-adoption.outcomes.2": "Consumers educated on capability features and benefits",
        "station.api-consumer-adoption.outcomes.3": "Improved consumer satisfaction and loyalty",
        "station.api-consumer-adoption.how_it_works": "Develop onboarding processes and resources to help consumers understand how to use reusable capabilities effectively.",
        "station.api-consumer-adoption.how_it_works.1": "Create educational materials that explain capability features, benefits, and usage patterns.",
        "station.api-consumer-adoption.how_it_works.2": "Engage with consumers through feedback loops, support channels, and communities to understand needs and improve adoption.",
        "station.api-promotion.title": "Promotion",
        "station.api-promotion.description": "Promote reusable capabilities to increase visibility, usage, and adoption among target audiences.",
        "station.api-promotion.why_it_matters": "Promotion increases visibility and drives usage. This station provides strategies and best practices for making target audiences aware of reusable capabilities and their value.",
        "station.api-promotion.apply_in_work": "Provide communication strategies, promotional materials, and community engagement resources. Ensure teams implement promotion practices that increase visibility, usage, and adoption among target audiences.",
        "station.api-promotion.outcomes": "Promotion strategies implemented",
        "station.api-promotion.outcomes.1": "Increased visibility and awareness",
        "station.api-promotion.outcomes.2": "Higher usage and adoption rates",
        "station.api-promotion.outcomes.3": "Improved consumer engagement and satisfaction",
        "station.api-promotion.how_it_works": "Develop communication strategies to promote reusable capabilities to target audiences, including internal channels, communities, demos, and enablement events.",
        "station.api-promotion.how_it_works.1": "Create promotional materials such as use cases, success stories, and release notes that highlight value and benefits.",
        "station.api-promotion.how_it_works.2": "Engage with relevant communities and forums to share updates, gather feedback, and promote usage.",
        "station.partner-integration.title": "Partner Integration - Collaborate with Partners",
        "station.partner-integration.description": "Facilitate partner integrations to enhance API capabilities and expand reach.",
        "station.partner-integration.why_it_matters": "Partner integrations can enhance API capabilities and expand reach. This station provides guidelines for collaborating with partners to integrate their APIs, ensuring seamless interoperability and value creation.",
        "station.partner-integration.apply_in_work": "Provide partner integration frameworks, guidelines, and monitoring tools. Ensure teams effectively collaborate with partners to enhance API capabilities, expand reach, and drive innovation.",
        "station.partner-integration.outcomes": "Partner integration processes established",
        "station.partner-integration.outcomes.1": "Enhanced API capabilities through partner APIs",
        "station.partner-integration.outcomes.2": "Expanded reach and market opportunities through partnerships",
        "station.partner-integration.outcomes.3": "Improved collaboration and innovation with partners",
        "station.partner-integration.how_it_works": "Identify potential partners whose APIs can enhance your API capabilities and value proposition.",
        "station.partner-integration.how_it_works.1": "Establish integration processes and guidelines for collaborating with partners, including technical integration, data sharing, and support.",
        "station.partner-integration.how_it_works.2": "Monitor partner API performance and compliance to ensure reliability and alignment with your API strategy.",
        "station.api-mindset.title": "API Mindset - Foster an API-First Culture",
        "station.api-mindset.description": "Cultivate an API-first mindset across the organization to drive innovation and collaboration.",
        "station.api-mindset.why_it_matters": "An API-first mindset is essential for fostering innovation and collaboration across the organization. This station provides strategies for cultivating an API-first culture, ensuring that APIs are seen as strategic assets that drive business value.",
        "station.api-mindset.apply_in_work": "Provide training programs, resources, and communication strategies to foster an API-first culture. Ensure teams understand the value of APIs and are empowered to drive API strategy and initiatives.",
        "station.api-mindset.outcomes": "API-first culture established across the organization",
        "station.api-mindset.outcomes.1": "Increased innovation and collaboration through APIs",
        "station.api-mindset.outcomes.2": "API teams empowered to drive API strategy and initiatives",
        "station.api-mindset.outcomes.3": "Improved alignment between business goals and API development",
        "station.api-mindset.how_it_works": "Promote the value of APIs as strategic assets that drive business value and innovation.",
        "station.api-mindset.how_it_works.1": "Encourage cross-functional collaboration between API teams, business units, and stakeholders to align API initiatives with business goals.",
        "station.api-mindset.how_it_works.2": "Provide training and resources to help teams adopt an API-first mindset  and understand the benefits of APIs.",
        "station.roles-and-responsibilities.title": "Roles and Responsibilities - Define API Team Structures",
        "station.roles-and-responsibilities.description": "Define clear roles and responsibilities for API teams to ensure effective collaboration and accountability.",
        "station.roles-and-responsibilities.why_it_matters": "Clear roles and responsibilities are essential for effective collaboration and accountability within API teams. This station provides guidelines for defining team structures, roles, and responsibilities, ensuring that everyone understands their contributions to API initiatives.",
        "station.roles-and-responsibilities.apply_in_work": "Provide team structure guidelines, role definitions, and communication strategies. Ensure teams have clear roles and responsibilities that promote effective collaboration and accountability in API initiatives.",
        "station.roles-and-responsibilities.outcomes": "Clear roles and responsibilities defined for API teams",
        "station.roles-and-responsibilities.outcomes.1": "Effective collaboration and accountability within API teams",
        "station.roles-and-responsibilities.outcomes.2": "Improved communication and alignment between team members",
        "station.roles-and-responsibilities.outcomes.3": "Reduced confusion and overlap in responsibilities",
        "station.roles-and-responsibilities.how_it_works": "Define team structures and roles for API teams, including API product owners, developers, architects, and operations.",
        "station.roles-and-responsibilities.how_it_works.1": "Establish clear responsibilities for each role, including API design, development, testing, and operations.",
        "station.roles-and-responsibilities.how_it_works.2": "Ensure roles and responsibilities are communicated to all team members and stakeholders to ensure alignment.",
        "station.upskilling.title": "Upskilling - Enhance API Skills and Knowledge",
        "station.upskilling.description": "Provide training and resources to enhance API skills and knowledge across the organization.",
        "station.upskilling.why_it_matters": "Continuous learning and upskilling are essential for keeping API teams updated with the latest technologies, practices, and trends. This station provides training programs and resources to enhance API skills and knowledge, ensuring teams are equipped to deliver high-quality APIs.",
        "station.upskilling.apply_in_work": "Provide training programs, resources, and assessment tools to enhance API skills and knowledge. Ensure teams have access to continuous learning opportunities that empower them to drive API innovation and quality.",
        "station.upskilling.outcomes": "API skills and knowledge enhanced across the organization",
        "station.upskilling.outcomes.1": "Increased proficiency in API design, development, and management",
        "station.upskilling.outcomes.2": "Improved ability to adopt new technologies and practices",
        "station.upskilling.outcomes.3": "Empowered teams to drive API innovation and quality",
        "station.upskilling.how_it_works": "Identify key API skills and knowledge areas that need enhancement, such as API design, security, and performance.",
        "station.operating-guidelines.title": "Operating Guidelines - Establish API Governance",
        "station.operating-guidelines.description": "Establish operating guidelines and governance practices to ensure consistent API management and quality.",
        "station.operating-guidelines.why_it_matters": "Effective API governance is essential for ensuring consistent API management, quality, and compliance. This station provides operating guidelines and governance practices that help teams manage APIs effectively, ensuring they align with organizational standards and best practices.",
        "station.operating-guidelines.apply_in_work": "Provide operating guidelines, governance frameworks, and monitoring tools for API management. Ensure teams follow established practices that promote consistent API management, quality, and compliance with organizational standards.",
        "station.operating-guidelines.outcomes": "API governance practices established",
        "station.operating-guidelines.outcomes.1": "Consistent API management and quality across the organization",
        "station.operating-guidelines.outcomes.2": "Compliance with organizational standards and best practices",
        "station.operating-guidelines.outcomes.3": "Improved visibility and control over API initiatives",
        "station.operating-guidelines.how_it_works": "Define operating guidelines based on APIOps Cycles that outline the processes, standards, and best practices for API management.",
        "station.operating-guidelines.how_it_works.1": "Establish governance practices that ensure APIs are managed consistently, including reviews, audits, and compliance checks.",
        "station.operating-guidelines.how_it_works.2": "Monitor API initiatives to ensure adherence to operating guidelines and governance practices",
        "station.portfolio-management.title": "Portfolio Management - Manage API Portfolio Effectively",
        "station.portfolio-management.description": "Manage the API portfolio effectively to ensure alignment with business goals and strategic initiatives.",
        "station.portfolio-management.why_it_matters": "Effective API portfolio management is essential for ensuring that APIs align with business goals and strategic initiatives. This station provides guidelines for managing the API portfolio, ensuring that APIs are prioritized, monitored, and optimized to deliver maximum value.",
        "station.portfolio-management.apply_in_work": "Provide portfolio management frameworks, prioritization criteria, and monitoring tools for API management. Ensure teams effectively manage the API portfolio, ensuring alignment with business goals, strategic initiatives, and delivering maximum value.",
        "station.portfolio-management.outcomes": "API portfolio management practices established",
        "station.portfolio-management.outcomes.1": "APIs aligned with business goals and strategic initiatives",
        "station.portfolio-management.outcomes.2": "Prioritization and optimization of APIs based on value and impact",
        "station.portfolio-management.outcomes.3": "Improved visibility and control over the API portfolio",
        "station.portfolio-management.how_it_works": "Define portfolio management practices that outline the processes for managing the API portfolio, including prioritization, monitoring, and optimization.",
        "station.budget-and-resource-management.title": "Budget and Resource Management - Optimize API Investments",
        "station.budget-and-resource-management.description": "Optimize budget and resource management for API initiatives to ensure effective investments and resource allocation.",
        "station.budget-and-resource-management.why_it_matters": "Effective budget and resource management is essential for ensuring that API initiatives are well-funded and resourced. This station provides guidelines for optimizing budget and resource management, ensuring that API initiatives are aligned with business goals and deliver maximum value.",
        "station.budget-and-resource-management.apply_in_work": "Provide budget management frameworks, prioritization criteria, and monitoring tools for API initiatives. Ensure teams effectively manage budgets and resources, optimizing investments in API development and management to deliver maximum value.",
        "station.budget-and-resource-management.outcomes": "Budget and resource management practices established for API initiatives",
        "station.budget-and-resource-management.outcomes.1": "Effective allocation of resources to API initiatives",
        "station.budget-and-resource-management.outcomes.2": "Optimized investments in API development and management",
        "station.budget-and-resource-management.outcomes.3": "Improved financial visibility and control over API initiatives",
        "station.budget-and-resource-management.how_it_works": "Define budget and resource management practices that outline the processes for managing budgets and resources for API initiatives.",
        "cycle.api-productization-cycle.station.api-product-strategy.title": "API Product Strategy - Turn APIs Into Strategic Products",
        "cycle.api-productization-cycle.station.api-product-strategy.why_it_matters": "Many organizations think of APIs as tech projects, not products. The result? Confused consumers, poor adoption, and wasted effort.\n\nThis station helps you define your API’s purpose, target audience, and success criteria, so teams can deliver APIs that solve real problems.",
        "cycle.api-productization-cycle.station.api-product-strategy.apply_in_work": "Provide guidelines and templates for creating API business models, value propositions, and roadmaps.",
        "cycle.api-productization-cycle.station.api-product-strategy.outcomes": "A straightforward API value proposition and audience",
        "cycle.api-productization-cycle.station.api-product-strategy.outcomes.1": "Shared language between product, design, and tech",
        "cycle.api-productization-cycle.station.api-product-strategy.outcomes.2": "A solid pitch or case for funding/approval",
        "cycle.api-productization-cycle.station.api-product-strategy.how_it_works": "Explore the customer or partner problem you expect to solve with APIs. Map the stakeholders, ther journeys and outcomes using the Customer Journey canvas.",
        "cycle.api-productization-cycle.station.api-product-strategy.how_it_works.1": "Define core entities, their attributes, and relationships to create a shared conceptual understanding across journeys and eventually APIs.",
        "cycle.api-productization-cycle.station.api-product-strategy.how_it_works.2": "Use the API Value Proposition Canvas to capture the supported business tasks and the API consumer pains, gains, and features that shape new or reusable APIs.",
        "cycle.api-productization-cycle.station.api-product-strategy.how_it_works.3": "Define the value — for users and the business with the API Business Model canvas to make your API strategy visual, shareable, and easy to validate with your API consumers at the next station.",
        "cycle.api-productization-cycle.station.api-consumer-experience.title": "API Consumer Experience - Design for Your API’s Real Users",
        "cycle.api-productization-cycle.station.api-consumer-experience.why_it_matters": "Great APIs don’t just work — they feel intuitive. Whether your consumer is an internal developer, external partner, or AI agent, their experience determines adoption.\n\nWithout a clear experience plan:\n- Great APIs go unused\n- Teams waste time guessing how to use your API\n- Feedback loops are broken or missing.\n\nThis station helps you see your API through the eyes of its consumers.",
        "cycle.api-productization-cycle.station.api-consumer-experience.how_it_works": "Review the existing API Value Proposition Canvas from the API consumer perspective. Keep the supported business tasks stable, and enrich the pain-relieving and gain-enabling features with API consumer concerns so they can guide later design decisions.",
        "cycle.api-productization-cycle.station.api-consumer-experience.how_it_works.1": "Use the Customer Journey Canvas for the API consumer journey from discovery and evaluation to onboarding, integration, troubleshooting, and ongoing use.",
        "cycle.api-productization-cycle.station.api-consumer-experience.how_it_works.2": "Use the resulting journey to improve onboarding, documentation, support, and feedback loops for the API consumer.",
        "cycle.api-productization-cycle.station.api-consumer-experience.apply_in_work": "Provide guidelines, tools, and feedback mechanisms for understanding, analyzing, and improving internal and external developer and partner experience.",
        "cycle.api-productization-cycle.station.api-consumer-experience.outcomes": "Identify and prioritize your API consumers",
        "cycle.api-productization-cycle.station.api-consumer-experience.outcomes.1": "Define the API experience journey",
        "cycle.api-productization-cycle.station.api-consumer-experience.outcomes.2": "Plan onboarding, documentation, and feedback",
        "cycle.api-productization-cycle.station.api-consumer-experience.outcomes.3": "Improve adoption through genuine empathy + Developer Experience (DX)",
        "cycle.api-productization-cycle.station.api-platform-architecture.title": "API Platform Architecture - Architect APIs for Scalability and Reuse",
        "cycle.api-productization-cycle.station.api-platform-architecture.why_it_matters": "When APIs scale across teams, your platform must enable governance and reuse without blocking speed. This station shows how to architect APIs for longevity, security, and efficiency.",
        "cycle.api-productization-cycle.station.api-platform-architecture.apply_in_work": "Establish a scalable, secure, and compliant infrastructure for API operations. Provide guidelines on architecture best practices.",
        "cycle.api-productization-cycle.station.api-platform-architecture.outcomes": "Cut redundant APIs and reduce cloud platform costs",
        "cycle.api-productization-cycle.station.api-platform-architecture.outcomes.1": "Implement consistent governance without heavy top-down control",
        "cycle.api-productization-cycle.station.api-platform-architecture.outcomes.2": "Design for internal reuse and external scalability",
        "cycle.api-productization-cycle.station.api-platform-architecture.how_it_works": "The Business Impact Canvas helps to identify and mitigate risks related to API availability, security, and functionality to support informed architectural decisions.",
        "cycle.api-productization-cycle.station.api-platform-architecture.how_it_works.1": "Map the regulatory, compliance, and network locations of API providers and consumers to ensure accessibility and compliance.",
        "cycle.api-productization-cycle.station.api-platform-architecture.how_it_works.2": "The Capacity Canvas aligns business transaction patterns, future consumption trends, and technical solutions to ensure API scalability and performance.It provides critical input for scaling decisions and infrastructure planning.",
        "cycle.api-productization-cycle.station.api-platform-architecture.how_it_works.3": "Define and monitor performance metrics (e.g., API calls, latency, error rates) and adoption metrics (e.g., NPS).",
        "cycle.api-productization-cycle.station.api-design.title": "API Design - Design APIs That Deliver Value",
        "cycle.api-productization-cycle.station.api-design.why_it_matters": "Designing APIs is not just about naming endpoints. Good design ensures APIs are usable, consistent, and aligned with business and technical goals. Poor design leads to tight coupling, low reuse, and costly rework across teams.",
        "cycle.api-productization-cycle.station.api-design.apply_in_work": "Provide reusable design patterns, shared standards, and validation tools for API specifications. Ensure design decisions are consistent, reviewed early, and aligned with business intent.",
        "cycle.api-productization-cycle.station.api-design.outcomes": "Well-documented and consistent API designs",
        "cycle.api-productization-cycle.station.api-design.outcomes.1": "Reusable and validated API contracts",
        "cycle.api-productization-cycle.station.api-design.outcomes.2": "Designs aligned with domain models and interaction patterns",
        "cycle.api-productization-cycle.station.api-design.outcomes.3": "Design traceability to business value",
        "cycle.api-productization-cycle.station.api-design.how_it_works": "Define core entities, their attributes, and relationships to create a shared conceptual understanding across APIs.",
        "cycle.api-productization-cycle.station.api-design.how_it_works.1": "Use the Interaction Canvas to define how consumers will interact with the API, ensuring it meets their needs and expectations.",
        "cycle.api-productization-cycle.station.api-design.how_it_works.2": "Apply REST design patterns to create consistent, reusable API contracts that are validated with stakeholders.",
        "cycle.api-productization-cycle.station.api-design.how_it_works.3": "Apply Event-driven design patterns to create consistent, reusable API contracts that are validated with stakeholders.",
        "cycle.api-productization-cycle.station.api-design.how_it_works.4": "Apply GraphQL design patterns to create consistent, reusable API contracts that are validated with stakeholders.",
        "cycle.api-productization-cycle.station.api-design.how_it_works.5": "Use the design principles and API style guide to align your design decisions with shared rules and enable consistent audit validation.",
        "cycle.api-productization-cycle.station.api-design.how_it_works.6": "Apply contract-first or design-first approaches to capture and validate the API contract before implementation.",
        "cycle.api-productization-cycle.station.api-design.how_it_works.7": "Use the API Audit Checklist to ensure the API design meets functional and non-functional requirements, including security, performance, and compliance.",
        "cycle.api-productization-cycle.station.api-delivery.title": "API Delivery - Deliver Secure and Reliable APIs",
        "cycle.api-productization-cycle.station.api-delivery.why_it_matters": "Even the best API designs fail if delivery is inconsistent. This station ensures your APIs are built with quality, tested thoroughly, and deployed reliably — enabling faster iterations and greater confidence.",
        "cycle.api-productization-cycle.station.api-delivery.apply_in_work": "Deliver coding frameworks, libraries, and standards for API implementation. Implement CI/CD pipelines, quality assurance frameworks, and deployment automation tools.",
        "cycle.api-productization-cycle.station.api-delivery.outcomes": "APIs implemented using tested frameworks and patterns",
        "cycle.api-productization-cycle.station.api-delivery.outcomes.1": "Reliable and automated CI/CD pipelines",
        "cycle.api-productization-cycle.station.api-delivery.outcomes.2": "Functional and non-functional testing integrated",
        "cycle.api-productization-cycle.station.api-delivery.outcomes.3": "Secure and compliant delivery pipelines",
        "cycle.api-productization-cycle.station.api-delivery.how_it_works": "Use API Development Best Practices as guidance for implementing the validated contract with established frameworks and libraries, ensuring the result is reusable and maintainable.",
        "cycle.api-productization-cycle.station.api-delivery.how_it_works.1": "Build the API implementation from the validated contract using established frameworks, libraries, and team standards.",
        "cycle.api-productization-cycle.station.api-delivery.how_it_works.2": "Test APIs for functionality, security, and performance using automated testing tools.",
        "cycle.api-productization-cycle.station.api-delivery.how_it_works.3": "Use CI/CD pipelines to automate build, test, and deployment processes, ensuring consistent quality and traceability.",
        "cycle.api-productization-cycle.station.api-delivery.how_it_works.4": "Ensure APIs meet security and compliance requirements through automated checks and audits.",
        "cycle.api-productization-cycle.station.api-delivery.how_it_works.5": "Use the API Audit Checklist to ensure the API meets functional and non-functional requirements, including security, performance, and compliance.",
        "cycle.api-productization-cycle.station.api-audit.title": "API Audit - Audit APIs for Compliance and Quality",
        "cycle.api-productization-cycle.station.api-audit.why_it_matters": "APIs are long-lived products and must meet expectations for quality, consistency, and compliance. The audit connects design decisions, implementation, and operational readiness to defined standards, reducing risk before exposure.",
        "cycle.api-productization-cycle.station.api-audit.apply_in_work": "Establish a consistent audit process that evaluates API readiness across lifecycle stages using defined criteria, evidence, and standards. Ensure gaps are identified early and resolved before release.",
        "cycle.api-productization-cycle.station.api-audit.outcomes": "APIs meet internal and external standards",
        "cycle.api-productization-cycle.station.api-audit.outcomes.1": "Clear documentation of API design and implementation decisions",
        "cycle.api-productization-cycle.station.api-audit.outcomes.2": "Security, performance, and compliance validated",
        "cycle.api-productization-cycle.station.api-audit.outcomes.3": "Reduced risk of issues in production",
        "cycle.api-productization-cycle.station.api-audit.how_it_works": "Conduct audits to ensure APIs meet organizational, technical, and legal standards before release.",
        "cycle.api-productization-cycle.station.api-audit.how_it_works.1": "Use checklists, linters, and testing tools to verify consistency and conformance with standards.",
        "cycle.api-productization-cycle.station.api-audit.how_it_works.2": "Collaborate with governance teams and domain experts to ensure APIs are ready for production.",
        "cycle.api-productization-cycle.station.api-publishing.title": "API Publishing - Publish APIs with Confidence",
        "cycle.api-productization-cycle.station.api-publishing.why_it_matters": "Publishing is more than deploying — it’s about discoverability, access, and support. If APIs aren't published correctly, they won’t be used, reused, or secured effectively.",
        "cycle.api-productization-cycle.station.api-publishing.apply_in_work": "Enable APIs to be published to the relevant environment and have clear registration and access mechanisms (e.g., API keys, OAuth, subscription plans) depending on the API consumer segments and security and compliance requirements.",
        "cycle.api-productization-cycle.station.api-publishing.outcomes": "APIs published in the right environment (private, partner, public)",
        "cycle.api-productization-cycle.station.api-publishing.outcomes.1": "Clear API onboarding and registration processes",
        "cycle.api-productization-cycle.station.api-publishing.outcomes.2": "Documentation, security models, and policies available",
        "cycle.api-productization-cycle.station.api-publishing.outcomes.3": "APIs ready for scale and governance",
        "cycle.api-productization-cycle.station.api-publishing.how_it_works": "Publish APIs to the appropriate gateways and environments to support reusability for multiple API consumers.",
        "cycle.api-productization-cycle.station.api-publishing.how_it_works.1": "Document how consumers find and use the API, including onboarding processes and registration.",
        "cycle.api-productization-cycle.station.api-publishing.how_it_works.2": "Ensure security models, gateway configuration, and legal terms are clear and accessible to consumers.",
        "cycle.api-productization-cycle.station.monitoring-and-improving.title": "Monitoring and Improving - for API Value",
        "cycle.api-productization-cycle.station.monitoring-and-improving.why_it_matters": "API delivery doesn’t stop at launch. Without monitoring, teams can’t improve adoption, performance, or ROI. This station ensures APIs remain useful, secure, and evolving with business needs.",
        "cycle.api-productization-cycle.station.monitoring-and-improving.apply_in_work": "Set up analytics frameworks to track performance and engagement. Develop feedback loops, analytics tools, and engagement strategies for APIs.",
        "cycle.api-productization-cycle.station.monitoring-and-improving.outcomes": "Performance and usage metrics defined and tracked",
        "cycle.api-productization-cycle.station.monitoring-and-improving.outcomes.1": "Developer feedback loops in place",
        "cycle.api-productization-cycle.station.monitoring-and-improving.outcomes.2": "Issues identified and addressed continuously",
        "cycle.api-productization-cycle.station.monitoring-and-improving.outcomes.3": "API iteration aligned with user needs",
        "cycle.api-productization-cycle.station.monitoring-and-improving.how_it_works": "Monitor performance metrics (e.g., API calls, latency, error rates) and adoption metrics (e.g., NPS).",
        "cycle.api-productization-cycle.station.monitoring-and-improving.how_it_works.1": "Analyze API usage metrics and incorporate user feedback into API iterations.",
        "cycle.api-productization-cycle.station.monitoring-and-improving.how_it_works.2": "Establish a habit of reviewing metrics and planning continuous improvement activities.",
        "resource.api-community-engagement-strategies.title": "API Community Engagement Strategies",
        "resource.api-community-engagement-strategies.description": "A playbook for fostering API adoption by cultivating communities through content, support channels, feedback loops, and social engagement strategies.",
        "resource.api-community-engagement-strategies.outcomes": "Shared understanding of the purpose and use of API Community Engagement Strategies",
        "resource.api-community-engagement-strategies.outcomes.1": "A consistent approach to applying API Community Engagement Strategies",
        "resource.api-community-engagement-strategies.outcomes.2": "Improved application of the related practices",
        "resource.api-community-engagement-strategies.steps": "Develop marketing strategies to promote APIs to target audiences, including social media, blogs, and webinars.",
        "resource.api-community-engagement-strategies.steps.1": "Create promotional materials (e.g., case studies, success stories) that highlight the value and benefits of APIs.",
        "resource.api-community-engagement-strategies.steps.2": "Create educational materials (e.g., tutorials, documentation) that explain API features, benefits, and usage patterns.",
        "resource.api-community-engagement-strategies.steps.3": "Engage with API consumers through feedback loops, support channels, and community forums to understand their needs and improve API adoption.",
        "resource.api-community-engagement-strategies.steps.4": "Analyze API usage metrics and incorporate user feedback into API iterations.",
        "resource.api-community-engagement-strategies.tips": "Adapt this resource to your context.",
        "resource.api-community-engagement-strategies.tips.1": "Use this resource collaboratively across relevant business and technical roles.",
        "resource.api-compliance-best-practices.title": "API Compliance Best Practices",
        "resource.api-compliance-best-practices.description": "Ensure APIs meet legal, regulatory, and internal compliance through documentation, controls, and automated validations.",
        "resource.api-compliance-best-practices.outcomes": "Shared understanding of the purpose and use of API Compliance Best Practices",
        "resource.api-compliance-best-practices.outcomes.1": "A consistent approach to applying API Compliance Best Practices",
        "resource.api-compliance-best-practices.outcomes.2": "Improved application of the related practices",
        "resource.api-compliance-best-practices.steps": "Document compliance measures and ensure they are communicated to stakeholders and consumers.",
        "resource.api-compliance-best-practices.steps.1": "Implement measures to ensure APIs comply with these requirements, including data encryption, access controls, and audit trails.",
        "resource.api-compliance-best-practices.steps.2": "Use checklists, linters, and testing tools to verify consistency and conformance with standards.",
        "resource.api-compliance-best-practices.tips": "Adapt this resource to your context.",
        "resource.api-compliance-best-practices.tips.1": "Use this resource collaboratively across relevant business and technical roles.",
        "resource.api-development-best-practices.title": "API Development Best Practices",
        "resource.api-development-best-practices.description": "Implementation guidance for turning a validated API interface contract into a consistent, maintainable API codebase using standard libraries, reusable patterns, and aligned development workflows.",
        "resource.api-development-best-practices.outcomes": "Shared understanding of the purpose and use of API Development Best Practices",
        "resource.api-development-best-practices.outcomes.1": "A consistent approach to applying API Development Best Practices",
        "resource.api-development-best-practices.outcomes.2": "Improved application of the related practices",
        "resource.api-development-best-practices.steps": "Apply these practices to the validated API interface contract and implementation plan before coding begins.",
        "resource.api-development-best-practices.steps.1": "Use established frameworks, libraries, and coding standards to implement the contract consistently and maintainably.",
        "resource.api-development-best-practices.tips": "Use this resource as implementation guidance and a review lens rather than as a required standalone artifact",
        "resource.api-development-best-practices.tips.1": "Use this resource collaboratively across relevant business and technical roles.",
        "resource.api-metrics-and-analytics.title": "API Metrics And Analytics",
        "resource.api-metrics-and-analytics.description": "A resource for defining, collecting, and analyzing API performance and usage data to align technical KPIs with business outcomes.",
        "resource.api-metrics-and-analytics.outcomes": "Shared understanding of the purpose and use of API Metrics And Analytics",
        "resource.api-metrics-and-analytics.outcomes.1": "A consistent approach to applying API Metrics And Analytics",
        "resource.api-metrics-and-analytics.outcomes.2": "Improved application of the related practices",
        "resource.api-metrics-and-analytics.steps": "Identify key performance indicators (KPIs) to measure API success against business goals.",
        "resource.api-metrics-and-analytics.steps.1": "Define and monitor performance metrics (e.g., API calls, latency, error rates) and adoption metrics (e.g., NPS).",
        "resource.api-metrics-and-analytics.steps.2": "Monitor API initiatives to ensure adherence to operating guidelines and governance practices",
        "resource.api-metrics-and-analytics.tips": "Adapt this resource to your context.",
        "resource.api-metrics-and-analytics.tips.1": "Use this resource collaboratively across relevant business and technical roles.",
        "resource.api-onboarding-best-practices.title": "API Onboarding Best Practices",
        "resource.api-onboarding-best-practices.description": "Best practices to streamline API consumer onboarding journeys with step-by-step registration, discovery, and first-call guidance.",
        "resource.api-onboarding-best-practices.outcomes": "Shared understanding of the purpose and use of API Onboarding Best Practices",
        "resource.api-onboarding-best-practices.outcomes.1": "A consistent approach to applying API Onboarding Best Practices",
        "resource.api-onboarding-best-practices.outcomes.2": "Improved application of the related practices",
        "resource.api-onboarding-best-practices.steps": "Define the API consumer journey from discovery to troubleshooting, identifying key touchpoints and pain points.",
        "resource.api-onboarding-best-practices.steps.1": "Develop onboarding processes and resources to help API consumers understand how to use APIs effectively.",
        "resource.api-onboarding-best-practices.steps.2": "Document how consumers find and use the API, including onboarding processes and registration.",
        "resource.api-onboarding-best-practices.tips": "Adapt this resource to your context.",
        "resource.api-onboarding-best-practices.tips.1": "Use this resource collaboratively across relevant business and technical roles.",
        "resource.api-portfolio-management-guidelines.title": "API Portfolio Management Guidelines",
        "resource.api-portfolio-management-guidelines.description": "A guide to strategically manage an organization's API suite—prioritizing APIs, allocating resources, and monitoring performance across lifecycles.",
        "resource.api-portfolio-management-guidelines.outcomes": "Shared understanding of the purpose and use of API Portfolio Management Guidelines",
        "resource.api-portfolio-management-guidelines.outcomes.1": "A consistent approach to applying API Portfolio Management Guidelines",
        "resource.api-portfolio-management-guidelines.outcomes.2": "Improved application of the related practices",
        "resource.api-portfolio-management-guidelines.steps": "Define portfolio management practices that outline the processes for managing the API portfolio, including prioritization, monitoring, and optimization.",
        "resource.api-portfolio-management-guidelines.steps.1": "Define budget and resource management practices that outline the processes for managing budgets and resources for API initiatives.",
        "resource.api-portfolio-management-guidelines.steps.2": "Establish criteria for evaluating and prioritizing budget allocations based on business value, impact, and alignment with strategic initiatives.",
        "resource.api-portfolio-management-guidelines.steps.3": "Monitor the API portfolio to ensure APIs are delivering value, meeting performance expectations, and aligning with business goals.",
        "resource.api-portfolio-management-guidelines.tips": "Adapt this resource to your context.",
        "resource.api-portfolio-management-guidelines.tips.1": "Use this resource collaboratively across relevant business and technical roles.",
        "resource.api-security-best-practices.title": "API Security Best Practices",
        "resource.api-security-best-practices.description": "A set of actionable controls for securing APIs, including authentication, authorization, encryption, rate-limiting, and pipeline-level compliance checks.",
        "resource.api-security-best-practices.outcomes": "Shared understanding of the purpose and use of API Security Best Practices",
        "resource.api-security-best-practices.outcomes.1": "A consistent approach to applying API Security Best Practices",
        "resource.api-security-best-practices.outcomes.2": "Improved application of the related practices",
        "resource.api-security-best-practices.steps": "Ensure APIs meet security and compliance requirements through automated checks and audits.",
        "resource.api-security-best-practices.steps.1": "Implement security measures such as authentication, authorization, encryption, and rate limiting to protect APIs from threats.",
        "resource.api-security-best-practices.steps.2": "Implement automated security checks and compliance validations in the CI/CD pipeline to ensure APIs are secure and compliant.",
        "resource.api-security-best-practices.tips": "Adapt this resource to your context.",
        "resource.api-security-best-practices.tips.1": "Use this resource collaboratively across relevant business and technical roles.",
        "resource.api-team-structure-guidelines.title": "API Team Structure Guidelines",
        "resource.api-team-structure-guidelines.description": "Organizational guidance for defining roles and responsibilities within API teams to ensure clarity, collaboration, and accountability.",
        "resource.api-team-structure-guidelines.outcomes": "Shared understanding of the purpose and use of API Team Structure Guidelines",
        "resource.api-team-structure-guidelines.outcomes.1": "A consistent approach to applying API Team Structure Guidelines",
        "resource.api-team-structure-guidelines.outcomes.2": "Improved application of the related practices",
        "resource.api-team-structure-guidelines.steps": "Define team structures and roles for API teams, including API product owners, developers, architects, and operations.",
        "resource.api-team-structure-guidelines.tips": "Adapt this resource to your context.",
        "resource.api-team-structure-guidelines.tips.1": "Use this resource collaboratively across relevant business and technical roles.",
        "resource.api-testing-best-practices.title": "API Testing Best Practices",
        "resource.api-testing-best-practices.description": "Guidelines for implementing automated functional, performance, and security testing throughout the API lifecycle.",
        "resource.api-testing-best-practices.outcomes": "Shared understanding of the purpose and use of API Testing Best Practices",
        "resource.api-testing-best-practices.outcomes.1": "A consistent approach to applying API Testing Best Practices",
        "resource.api-testing-best-practices.outcomes.2": "Improved application of the related practices",
        "resource.api-testing-best-practices.steps": "Test APIs for functionality, security, and performance using automated testing tools.",
        "resource.api-testing-best-practices.steps.1": "Integrate functional and non-functional testing into the CI/CD pipeline to ensure APIs meet quality standards.",
        "resource.api-testing-best-practices.steps.2": "Use automated testing tools to validate API functionality, security, and performance.",
        "resource.api-testing-best-practices.tips": "Adapt this resource to your context.",
        "resource.api-testing-best-practices.tips.1": "Use this resource collaboratively across relevant business and technical roles.",
        "resource.api-training-programs.title": "API Training Programs",
        "resource.api-training-programs.description": "A roadmap for upskilling teams with structured learning paths in API design, governance, performance, and security.",
        "resource.api-training-programs.outcomes": "Shared understanding of the purpose and use of API Training Programs",
        "resource.api-training-programs.outcomes.1": "A consistent approach to applying API Training Programs",
        "resource.api-training-programs.outcomes.2": "Improved application of the related practices",
        "resource.api-training-programs.steps": "Identify key API skills and knowledge areas that need enhancement, such as API design, security, and performance.",
        "resource.api-training-programs.steps.1": "Encourage continuous learning through online courses, certifications, and community engagement.",
        "resource.api-training-programs.steps.2": "Provide training and resources to help teams adopt an API-first mindset and understand the benefits of APIs.",
        "resource.api-training-programs.steps.3": "Provide training programs, workshops, and resources to help teams enhance their API skills and knowledge.",
        "resource.api-training-programs.tips": "Adapt this resource to your context.",
        "resource.api-training-programs.tips.1": "Use this resource collaboratively across relevant business and technical roles.",
        "resource.api-versioning-best-practices.title": "API Versioning Best Practices",
        "resource.api-versioning-best-practices.description": "Strategies for introducing, maintaining, and retiring API versions while preserving backward compatibility and consumer trust.",
        "resource.api-versioning-best-practices.outcomes": "Shared understanding of the purpose and use of API Versioning Best Practices",
        "resource.api-versioning-best-practices.outcomes.1": "A consistent approach to applying API Versioning Best Practices",
        "resource.api-versioning-best-practices.outcomes.2": "Improved application of the related practices",
        "resource.api-versioning-best-practices.steps": "Define versioning strategies for APIs to manage changes and ensure backward compatibility.",
        "resource.api-versioning-best-practices.tips": "Adapt this resource to your context.",
        "resource.api-versioning-best-practices.tips.1": "Use this resource collaboratively across relevant business and technical roles.",
        "resource.apiops-CI-CD-for-apis.title": "APIOps CI/CD For APIs",
        "resource.apiops-CI-CD-for-apis.description": "Deployment guidance that integrates API lifecycle tasks—design, testing, governance—into continuous integration and delivery pipelines.",
        "resource.apiops-CI-CD-for-apis.outcomes": "Shared understanding of the purpose and use of APIOps CI/CD For APIs",
        "resource.apiops-CI-CD-for-apis.outcomes.1": "A consistent approach to applying APIOps CI/CD For APIs",
        "resource.apiops-CI-CD-for-apis.outcomes.2": "Improved application of the related practices",
        "resource.apiops-CI-CD-for-apis.steps": "Use CI/CD pipelines to automate build, test, and deployment processes, ensuring consistent quality and traceability.",
        "resource.apiops-CI-CD-for-apis.steps.1": "Integrate automated tests into the CI/CD pipeline to ensure continuous validation of API quality.",
        "resource.apiops-CI-CD-for-apis.steps.2": "Implement deployment strategies (e.g., blue-green deployments, canary releases) to minimize risks during API releases.",
        "resource.apiops-CI-CD-for-apis.steps.3": "Establish a habit of reviewing metrics and planning continuous improvement activities.",
        "resource.apiops-CI-CD-for-apis.tips": "Adapt this resource to your context.",
        "resource.apiops-CI-CD-for-apis.tips.1": "Use this resource collaboratively across relevant business and technical roles.",
        "resource.competitor-analysis-template.title": "Competitor Analysis Template",
        "resource.competitor-analysis-template.description": "A structured worksheet to benchmark your API offerings against competitors by mapping strengths, weaknesses, and value differentiators.",
        "resource.competitor-analysis-template.outcomes": "Shared understanding of the purpose and use of Competitor Analysis Template",
        "resource.competitor-analysis-template.outcomes.1": "A consistent approach to applying Competitor Analysis Template",
        "resource.competitor-analysis-template.outcomes.2": "Improved application of the related practices",
        "resource.competitor-analysis-template.steps": "Conduct a competitive analysis to identify key competitors, and their API offerings.",
        "resource.competitor-analysis-template.steps.1": "Analyze competitor APIs to understand their strengths, weaknesses, and unique selling points.",
        "resource.competitor-analysis-template.tips": "Adapt this resource to your context.",
        "resource.competitor-analysis-template.tips.1": "Use this resource collaboratively across relevant business and technical roles.",
        "resource.contract-first-design.title": "Contract First Design",
        "resource.contract-first-design.description": "A guideline advocating for API-first approaches using formal contracts (e.g., OpenAPI) to align stakeholders before development.",
        "resource.contract-first-design.outcomes": "Shared understanding of the purpose and use of Contract First Design",
        "resource.contract-first-design.outcomes.1": "A consistent approach to applying Contract First Design",
        "resource.contract-first-design.outcomes.2": "Improved application of the related practices",
        "resource.contract-first-design.steps": "Apply contract-first or design-first approaches to ensure API interface contracts are validated before implementation.",
        "resource.contract-first-design.steps.1": "Define API interface contracts that outline the expectations, responsibilities, and usage guidelines for each API.",
        "resource.contract-first-design.steps.2": "Use standardized formats (e.g., OpenAPI, AsyncAPI) to create machine-readable API interface contracts that are easy to share and validate.",
        "resource.contract-first-design.tips": "Adapt this resource to your context.",
        "resource.contract-first-design.tips.1": "Use this resource collaboratively across relevant business and technical roles.",
        "resource.cross-functional-collaboration-best-practices.title": "Cross Functional Collaboration Best Practices",
        "resource.cross-functional-collaboration-best-practices.description": "Practices to facilitate communication and alignment between business and tech teams when planning or delivering APIs.",
        "resource.cross-functional-collaboration-best-practices.outcomes": "Shared understanding of the purpose and use of Cross Functional Collaboration Best Practices",
        "resource.cross-functional-collaboration-best-practices.outcomes.1": "A consistent approach to applying Cross Functional Collaboration Best Practices",
        "resource.cross-functional-collaboration-best-practices.outcomes.2": "Improved application of the related practices",
        "resource.cross-functional-collaboration-best-practices.steps": "Encourage cross-functional collaboration between API teams, business units, and stakeholders to align API initiatives with business goals.",
        "resource.cross-functional-collaboration-best-practices.tips": "Adapt this resource to your context.",
        "resource.cross-functional-collaboration-best-practices.tips.1": "Use this resource collaboratively across relevant business and technical roles.",
        "resource.data-privacy-guidelines.title": "Data Privacy Guidelines",
        "resource.data-privacy-guidelines.description": "Design considerations to ensure APIs meet data protection regulations like GDPR through anonymization and access controls.",
        "resource.data-privacy-guidelines.outcomes": "Shared understanding of the purpose and use of Data Privacy Guidelines",
        "resource.data-privacy-guidelines.outcomes.1": "A consistent approach to applying Data Privacy Guidelines",
        "resource.data-privacy-guidelines.outcomes.2": "Improved application of the related practices",
        "resource.data-privacy-guidelines.steps": "Ensure user data privacy by implementing data protection measures, such as anonymization and access controls.",
        "resource.data-privacy-guidelines.tips": "Adapt this resource to your context.",
        "resource.data-privacy-guidelines.tips.1": "Use this resource collaboratively across relevant business and technical roles.",
        "resource.domain-canvas.title": "Domain Canvas",
        "resource.domain-canvas.description": "A modeling tool to define and communicate the key entities and relationships in your domain, ensuring semantic consistency across capabilities, integrations, APIs, data products, and services.",
        "resource.domain-canvas.outcomes": "Shared domain model and terminology",
        "resource.domain-canvas.outcomes.1": "Core entities, relationships, rules, and ownership clarified",
        "resource.domain-canvas.outcomes.2": "Semantic consistency across capabilities, integrations, APIs, data products, and services",
        "resource.domain-canvas.steps": "Define core entities, their attributes, and relationships to create a shared conceptual understanding across capabilities, integrations, APIs, data products, and services.",
        "resource.domain-canvas.tips": "Use business language first; map it to technical models only after the domain is understood.",
        "resource.domain-canvas.tips.1": "Validate the model with domain experts, producers, and consumers.",
        "resource.ecosystem-vision-template.title": "Ecosystem Vision Template",
        "resource.ecosystem-vision-template.description": "A strategic planning tool to define the API ecosystem, including target partners, value chains, and integration opportunities.",
        "resource.ecosystem-vision-template.outcomes": "Shared understanding of the purpose and use of Ecosystem Vision Template",
        "resource.ecosystem-vision-template.outcomes.1": "A consistent approach to applying Ecosystem Vision Template",
        "resource.ecosystem-vision-template.outcomes.2": "Improved application of the related practices",
        "resource.ecosystem-vision-template.steps": "Conduct market research to identify trends, opportunities, and threats in the API landscape.",
        "resource.ecosystem-vision-template.steps.1": "Identify key ecosystem partners and stakeholders who will benefit from or contribute to the ecosystem.",
        "resource.ecosystem-vision-template.steps.2": "Identify gaps in the market that your APIs can fill, based on competitor offerings.",
        "resource.ecosystem-vision-template.steps.3": "Identify potential partners whose APIs can enhance your API capabilities and value proposition.",
        "resource.ecosystem-vision-template.steps.4": "Develop a differentiation strategy that highlights unique features and benefits of your APIs.",
        "resource.ecosystem-vision-template.steps.5": "Define the ecosystem vision for your APIs, including how they will interact with other systems and platforms.",
        "resource.ecosystem-vision-template.steps.6": "Design APIs to enable seamless integration and collaboration within the ecosystem.",
        "resource.ecosystem-vision-template.tips": "Adapt this resource to your context.",
        "resource.ecosystem-vision-template.tips.1": "Use this resource collaboratively across relevant business and technical roles.",
        "resource.industry-standards-and-best-practices.title": "Industry Standards And Best Practices",
        "resource.industry-standards-and-best-practices.description": "A reference resource for aligning API design and operation with widely recognized industry frameworks and specifications.",
        "resource.industry-standards-and-best-practices.outcomes": "Shared understanding of the purpose and use of Industry Standards And Best Practices",
        "resource.industry-standards-and-best-practices.outcomes.1": "A consistent approach to applying Industry Standards And Best Practices",
        "resource.industry-standards-and-best-practices.outcomes.2": "Improved application of the related practices",
        "resource.industry-standards-and-best-practices.steps": "Identify industry standards and best practices to ensure APIs are competitive and compliant.",
        "resource.industry-standards-and-best-practices.tips": "Adapt this resource to your context.",
        "resource.industry-standards-and-best-practices.tips.1": "Use this resource collaboratively across relevant business and technical roles.",
        "resource.partner-integration-guidelines.title": "Partner Integration Guidelines",
        "resource.partner-integration-guidelines.description": "Integration checklists and communication patterns to manage technical and legal aspects of third-party API relationships.",
        "resource.partner-integration-guidelines.outcomes": "Shared understanding of the purpose and use of Partner Integration Guidelines",
        "resource.partner-integration-guidelines.outcomes.1": "A consistent approach to applying Partner Integration Guidelines",
        "resource.partner-integration-guidelines.outcomes.2": "Improved application of the related practices",
        "resource.partner-integration-guidelines.steps": "Establish integration processes and guidelines for collaborating with partners, including technical integration, data sharing, and support.",
        "resource.partner-integration-guidelines.steps.1": "Monitor partner API performance and compliance to ensure reliability and alignment with your API strategy.",
        "resource.partner-integration-guidelines.tips": "Adapt this resource to your context.",
        "resource.partner-integration-guidelines.tips.1": "Use this resource collaboratively across relevant business and technical roles.",
        "resource.role-communication-best-practices.title": "Role Communication Best Practices",
        "resource.role-communication-best-practices.description": "Tools to define and document who is responsible for what within API initiatives, ensuring handoffs and accountability are clear.",
        "resource.role-communication-best-practices.outcomes": "Shared understanding of the purpose and use of Role Communication Best Practices",
        "resource.role-communication-best-practices.outcomes.1": "A consistent approach to applying Role Communication Best Practices",
        "resource.role-communication-best-practices.outcomes.2": "Improved application of the related practices",
        "resource.role-communication-best-practices.steps": "Establish clear responsibilities for each role, including API design, development, testing, and operations.",
        "resource.role-communication-best-practices.steps.1": "Ensure roles and responsibilities are communicated to all team members and stakeholders to ensure alignment.",
        "resource.role-communication-best-practices.tips": "Adapt this resource to your context.",
        "resource.role-communication-best-practices.tips.1": "Use this resource collaboratively across relevant business and technical roles.",
        "resource.scalable-infrastructure-best-practices.title": "Scalable Infrastructure Best Practices",
        "resource.scalable-infrastructure-best-practices.description": "Architectural guidance to ensure APIs are deployed on infrastructure that can elastically handle usage spikes and growth.",
        "resource.scalable-infrastructure-best-practices.outcomes": "Shared understanding of the purpose and use of Scalable Infrastructure Best Practices",
        "resource.scalable-infrastructure-best-practices.outcomes.1": "A consistent approach to applying Scalable Infrastructure Best Practices",
        "resource.scalable-infrastructure-best-practices.outcomes.2": "Improved application of the related practices",
        "resource.scalable-infrastructure-best-practices.steps": "Design API infrastructure to be scalable and resilient, using cloud-native patterns and technologies.",
        "resource.scalable-infrastructure-best-practices.steps.1": "Monitor infrastructure performance and capacity to ensure it can handle growing demand.",
        "resource.scalable-infrastructure-best-practices.tips": "Adapt this resource to your context.",
        "resource.scalable-infrastructure-best-practices.tips.1": "Use this resource collaboratively across relevant business and technical roles.",
        "resource.service-agreement-template.title": "Service Agreement Template",
        "resource.service-agreement-template.description": "A customizable agreement format that defines expectations, SLAs, responsibilities, and access terms for API consumption.",
        "resource.service-agreement-template.outcomes": "Shared understanding of the purpose and use of Service Agreement Template",
        "resource.service-agreement-template.outcomes.1": "A consistent approach to applying Service Agreement Template",
        "resource.service-agreement-template.outcomes.2": "Improved application of the related practices",
        "resource.service-agreement-template.steps": "Define service agreements that outline the expectations, service levels, and responsibilities for each API.",
        "resource.service-agreement-template.steps.1": "Use standardized formats to create machine-readable service agreements that are easy to share and validate.",
        "resource.service-agreement-template.steps.2": "Ensure service agreements are reviewed and approved by stakeholders to ensure alignment and clarity.",
        "resource.service-agreement-template.tips": "Adapt this resource to your context.",
        "resource.service-agreement-template.tips.1": "Use this resource collaboratively across relevant business and technical roles.",
        "resource.stakeholder-engagement-best-practices.title": "Stakeholder Engagement Best Practices",
        "resource.stakeholder-engagement-best-practices.description": "Engagement tactics for aligning internal and external stakeholders around shared API goals, value, and governance.",
        "resource.stakeholder-engagement-best-practices.outcomes": "Shared understanding of the purpose and use of Stakeholder Engagement Best Practices",
        "resource.stakeholder-engagement-best-practices.outcomes.1": "A consistent approach to applying Stakeholder Engagement Best Practices",
        "resource.stakeholder-engagement-best-practices.outcomes.2": "Improved application of the related practices",
        "resource.stakeholder-engagement-best-practices.steps": "Engage stakeholders to ensure alignment and support for API initiatives.",
        "resource.stakeholder-engagement-best-practices.tips": "Adapt this resource to your context.",
        "resource.stakeholder-engagement-best-practices.tips.1": "Use this resource collaboratively across relevant business and technical roles.",
        "resource.test-automation-frameworks.title": "Test Automation Frameworks",
        "resource.test-automation-frameworks.description": "Recommended tools and patterns for automating API interface contract, regression, and integration testing across environments.",
        "resource.test-automation-frameworks.outcomes": "Shared understanding of the purpose and use of Test Automation Frameworks",
        "resource.test-automation-frameworks.outcomes.1": "A consistent approach to applying Test Automation Frameworks",
        "resource.test-automation-frameworks.outcomes.2": "Improved application of the related practices",
        "resource.test-automation-frameworks.steps": "Implement test automation frameworks that support contract testing, integration testing, and end-to-end testing.",
        "resource.test-automation-frameworks.tips": "Adapt this resource to your context.",
        "resource.test-automation-frameworks.tips.1": "Use this resource collaboratively across relevant business and technical roles.",
        "resource.vendor-management-best-practices.title": "Vendor Management Best Practices",
        "resource.vendor-management-best-practices.description": "Framework for evaluating and managing external API vendors and third-party integrations based on risk, performance, and compliance.",
        "resource.vendor-management-best-practices.outcomes": "Shared understanding of the purpose and use of Vendor Management Best Practices",
        "resource.vendor-management-best-practices.outcomes.1": "A consistent approach to applying Vendor Management Best Practices",
        "resource.vendor-management-best-practices.outcomes.2": "Improved application of the related practices",
        "resource.vendor-management-best-practices.steps": "Establish vendor management processes to evaluate, onboard, and monitor third-party API vendors.",
        "resource.vendor-management-best-practices.steps.1": "Define criteria for evaluating vendor APIs, including reliability, security, and compliance.",
        "resource.vendor-management-best-practices.tips": "Adapt this resource to your context.",
        "resource.vendor-management-best-practices.tips.1": "Use this resource collaboratively across relevant business and technical roles.",
        "resource.api-audit-checklist.title": "API Audit Checklist",
        "resource.api-audit-checklist.description": "A lifecycle-based checklist to verify API readiness across design, delivery, publishing, and compliance using defined audit criteria and evidence.",
        "resource.api-audit-checklist.outcomes": "Shared understanding of the purpose and use of API Audit Checklist",
        "resource.api-audit-checklist.outcomes.1": "A consistent approach to applying API Audit Checklist",
        "resource.api-audit-checklist.outcomes.2": "Improved application of the related practices",
        "resource.api-audit-checklist.steps": "Use the API Audit Checklist to ensure the API design meets functional and non-functional requirements, including security, performance, and compliance.",
        "resource.api-audit-checklist.steps.1": "Conduct audits to assess lifecycle coverage and verify that the API meets business, design, and operational standards.",
        "resource.api-audit-checklist.steps.2": "Ensure that documentation, security models, gateway configuration, and legal requirements are clearly defined, validated, and supported by evidence.",
        "resource.api-audit-checklist.tips": "Each audit item links lifecycle work (stations), governing guidelines, and supporting evidence to provide a clear view of API readiness.",
        "resource.api-audit-checklist.tips.1": "Use the API Audit Checklist collaboratively across business and tech roles",
        "resource.api-business-model-canvas.title": "API Business Model Canvas",
        "resource.api-business-model-canvas.description": "Strategically assess API business viability by mapping value propositions, consumer segments, and key resources.",
        "resource.api-business-model-canvas.outcomes": "Clear business strategy for APIs",
        "resource.api-business-model-canvas.outcomes.1": "Identification of key resources and partners",
        "resource.api-business-model-canvas.outcomes.2": "Alignment of API features with business goals",
        "resource.api-business-model-canvas.steps": "Summarize the API's value proposition",
        "resource.api-business-model-canvas.steps.1": "Define consumer segments",
        "resource.api-business-model-canvas.steps.2": "Identify developer relations strategies",
        "resource.api-business-model-canvas.steps.3": "Map distribution channels",
        "resource.api-business-model-canvas.steps.4": "Document key resources and activities",
        "resource.api-business-model-canvas.steps.5": "Identify key partners and stakeholders",
        "resource.api-business-model-canvas.steps.6": "Highlight benefits and costs",
        "resource.api-business-model-canvas.tips": "Start with a single API to ensure clarity",
        "resource.api-business-model-canvas.tips.1": "Use metrics like cost vs. benefit to prioritize opportunities",
        "resource.api-business-model-canvas.tips.2": "Validate outputs with key stakeholders",
        "resource.api-design-principles.title": "API Design Principles",
        "resource.api-design-principles.description": "A concise guide to API usability, discoverability, and consistency grounded in shared design rules and real consumer needs.",
        "resource.api-design-principles.outcomes": "Shared understanding of the purpose and use of API Design Principles",
        "resource.api-design-principles.outcomes.1": "A consistent approach to applying API Design Principles",
        "resource.api-design-principles.outcomes.2": "Improved application of the related practices",
        "resource.api-design-principles.steps": "**Consumer-first design:** start every APIOps cycle by gathering user goals and domain terms so APIs solve real problems.",
        "resource.api-design-principles.steps.1": "**Consistent naming and behavior:** apply shared conventions for resources, errors and formats to make APIs predictable.",
        "resource.api-design-principles.steps.2": "**Contract driven:** capture the interface with OpenAPI or AsyncAPI before coding to align teams and enable automation.",
        "resource.api-design-principles.steps.3": "**Usability and discoverability:** provide clear documentation and examples so developers quickly understand how to use the API.",
        "resource.api-design-principles.steps.4": "**Iterate safely:** evolve designs in small, versioned increments so changes do not disrupt existing consumers.",
        "resource.api-design-principles.tips": "Adapt this resource to your context.",
        "resource.api-design-principles.tips.1": "Use this resource collaboratively across relevant business and technical roles.",
        "resource.api-value-proposition-canvas.title": "API Value Proposition Canvas",
        "resource.api-value-proposition-canvas.description": "Align API features with user needs by mapping tasks, pains, and gains to API products.",
        "resource.api-value-proposition-canvas.outcomes": "Focused feature development",
        "resource.api-value-proposition-canvas.outcomes.1": "Alignment with user needs",
        "resource.api-value-proposition-canvas.outcomes.2": "Improved API consumer satisfaction",
        "resource.api-value-proposition-canvas.steps": "List user journey tasks",
        "resource.api-value-proposition-canvas.steps.1": "Identify features delivering expected gains",
        "resource.api-value-proposition-canvas.steps.2": "Define features addressing challenges",
        "resource.api-value-proposition-canvas.steps.3": "Map features to API products",
        "resource.api-value-proposition-canvas.tips": "Use input from the Customer Journey Canvas",
        "resource.api-value-proposition-canvas.tips.1": "Highlight features that relieve pains or enhance gains",
        "resource.api-value-proposition-canvas.tips.2": "Validate features with API consumers to ensure alignment",
        "resource.business-impact-canvas.title": "Business Impact Canvas",
        "resource.business-impact-canvas.description": "Identify business, availability, security, data, compliance, and operational risks that should shape architecture and platform decisions.",
        "resource.business-impact-canvas.outcomes": "Documented business and operational impact assessment",
        "resource.business-impact-canvas.outcomes.1": "Prioritized risks and mitigation actions",
        "resource.business-impact-canvas.outcomes.2": "Evidence for architecture and platform decisions",
        "resource.business-impact-canvas.steps": "Availability Risks: Identify risks and impacts.",
        "resource.business-impact-canvas.steps.1": "Ways to Mitigate Availability Risks: Define mitigation measures.",
        "resource.business-impact-canvas.steps.2": "Security Risks: Document security-related risks.",
        "resource.business-impact-canvas.steps.3": "Ways to Mitigate Security Risks: Propose strategies to mitigate security risks.",
        "resource.business-impact-canvas.steps.4": "Data Risks: Identify risks to data accuracy or availability.",
        "resource.business-impact-canvas.steps.5": "Ways to Mitigate Data Risks: Plan strategies to address data risks.",
        "resource.business-impact-canvas.tips": "Complete this before selecting or confirming the implementation style.",
        "resource.business-impact-canvas.tips.1": "Review the risks with both business and technical stakeholders.",
        "resource.business-impact-canvas.tips.2": "Use past incidents and operational evidence to challenge assumptions.",
        "resource.capacity-canvas.title": "Capacity Canvas",
        "resource.capacity-canvas.description": "Plan capacity for current and future demand, including volumes, peaks, latency, availability, scaling, caching, and rate limits for the selected capability and implementation style.",
        "resource.capacity-canvas.outcomes": "Capacity requirements aligned with expected business demand",
        "resource.capacity-canvas.outcomes.1": "Peak-load, availability, and growth assumptions documented",
        "resource.capacity-canvas.outcomes.2": "Scaling, caching, and rate-limiting decisions defined",
        "resource.capacity-canvas.steps": "Document current business volumes",
        "resource.capacity-canvas.steps.1": "Forecast future consumption trends",
        "resource.capacity-canvas.steps.2": "Plan for peak load and availability requirements",
        "resource.capacity-canvas.steps.3": "Define caching and rate-limiting strategies",
        "resource.capacity-canvas.steps.4": "Propose scaling strategies",
        "resource.capacity-canvas.tips": "Complete this before finalizing architecture and platform decisions.",
        "resource.capacity-canvas.tips.1": "Use measured data where available and state assumptions explicitly.",
        "resource.capacity-canvas.tips.2": "Revisit the canvas after pilots or material changes in demand.",
        "resource.customer-journey-canvas.title": "Customer Journey Canvas",
        "resource.customer-journey-canvas.description": "Map customer, partner, or consumer journeys to identify needs, pain points, gains, inputs, outputs, and experience expectations.",
        "resource.customer-journey-canvas.outcomes": "Shared understanding of the customer, partner, or consumer journey",
        "resource.customer-journey-canvas.outcomes.1": "Needs, pain points, gains, inputs, and outputs documented",
        "resource.customer-journey-canvas.outcomes.2": "Journey evidence available for capability, requirements, and architecture decisions",
        "resource.customer-journey-canvas.steps": "Define customer persona",
        "resource.customer-journey-canvas.steps.1": "Identify triggers for the journey",
        "resource.customer-journey-canvas.steps.2": "Describe the journey's end",
        "resource.customer-journey-canvas.steps.3": "Map journey steps with inputs/outputs",
        "resource.customer-journey-canvas.steps.4": "Identify customer pains",
        "resource.customer-journey-canvas.steps.5": "Summarize customer gains",
        "resource.customer-journey-canvas.steps.6": "Define necessary inputs and resulting outputs",
        "resource.customer-journey-canvas.steps.7": "Define interactions and processing expectations for each step",
        "resource.customer-journey-canvas.tips": "Validate the journey with people who perform or experience it.",
        "resource.customer-journey-canvas.tips.1": "Use the results to inform value proposition, domain, requirements, and architecture work.",
        "resource.event-canvas.title": "Event Canvas",
        "resource.event-canvas.description": "Design event-driven interfaces and integrations by defining events, triggers, schemas, producers, consumers, and processing logic.",
        "resource.event-canvas.outcomes": "Defined event-driven interaction model",
        "resource.event-canvas.outcomes.1": "Events, triggers, schemas, producers, and consumers clarified",
        "resource.event-canvas.outcomes.2": "Processing, acknowledgement, and failure expectations documented",
        "resource.event-canvas.steps": "Identify key events in the system",
        "resource.event-canvas.steps.1": "Define triggers for each event",
        "resource.event-canvas.steps.2": "Describe event processing, state changes, and failure handling.",
        "resource.event-canvas.steps.3": "Specify resulting outputs or acknowledgments",
        "resource.event-canvas.tips": "Use event schemas to standardize event formats",
        "resource.event-canvas.tips.1": "Document event flows, ownership, ordering assumptions, and dependencies.",
        "resource.event-canvas.tips.2": "Validate event processing with test cases",
        "resource.graphql-canvas.title": "GraphQL Canvas",
        "resource.graphql-canvas.description": "Design GraphQL APIs by defining types, queries, mutations, and subscriptions.",
        "resource.graphql-canvas.outcomes": "Structured GraphQL API design",
        "resource.graphql-canvas.outcomes.1": "Defined types and their relationships",
        "resource.graphql-canvas.outcomes.2": "Clear queries, mutations, and subscriptions",
        "resource.graphql-canvas.steps": "What problems are API consumers trying to solve? What data do they need?",
        "resource.graphql-canvas.steps.1": "Define GraphQL types and their attributes: What are the core types exposed (e.g., User, Order, Product)?",
        "resource.graphql-canvas.steps.2": "Map relationships between types: How do types relate to each other in nested queries?",
        "resource.graphql-canvas.steps.3": "Specify queries for data retrieval",
        "resource.graphql-canvas.steps.4": "Define mutations for data modification: What operations will modify data (e.g., create, update, delete)?",
        "resource.graphql-canvas.steps.5": "Outline subscriptions for real-time updates",
        "resource.graphql-canvas.steps.6": "Define authentication and authorization: Who can access which fields or types?",
        "resource.graphql-canvas.steps.7": "Consider if there are any pagination, filtering, or rate-limiting constraints",
        "resource.graphql-canvas.tips": "Use introspection to validate type definitions",
        "resource.graphql-canvas.tips.1": "Document example queries and mutations",
        "resource.graphql-canvas.tips.2": "Ensure type names are descriptive and consistent",
        "resource.interaction-canvas.title": "Interaction Canvas",
        "resource.interaction-canvas.description": "Define interactions, workflows, inputs, outputs, commands, queries, events, and expected responses to ensure a consistent consumer experience.",
        "resource.interaction-canvas.outcomes": "Defined interaction model for the selected capability",
        "resource.interaction-canvas.outcomes.1": "Inputs, outputs, commands, queries, events, and responses clarified",
        "resource.interaction-canvas.outcomes.2": "Validation rules and interaction expectations agreed",
        "resource.interaction-canvas.steps": "Map interactions to user, consumer, or system tasks",
        "resource.interaction-canvas.steps.1": "Define access points, operations, commands, queries, or events for each interaction",
        "resource.interaction-canvas.steps.2": "Document inputs and outputs for each interaction.",
        "resource.interaction-canvas.steps.3": "Specify validation rules and constraints",
        "resource.interaction-canvas.steps.4": "Create interaction models for CRUD, query-driven, command-driven, and event-driven interactions",
        "resource.interaction-canvas.tips": "Start with common use cases before handling edge cases",
        "resource.interaction-canvas.tips.1": "Simulate interactions with mock data to validate workflows",
        "resource.interaction-canvas.tips.2": "Document expected responses for successful, unsuccessful, and exceptional interactions.",
        "resource.location-canvas.title": "Location Canvas",
        "resource.location-canvas.description": "Map consumer, producer, system, data, network, regulatory, and trust-boundary locations to ensure compliance and performance across regions.",
        "resource.location-canvas.outcomes": "Documented location, residency, network, and regulatory requirements",
        "resource.location-canvas.outcomes.1": "Regional performance and accessibility constraints identified",
        "resource.location-canvas.outcomes.2": "Data residency, trust boundaries, and applicable regulations clarified",
        "resource.location-canvas.steps": "Map locations of producers, source systems, platforms, and consumers.",
        "resource.location-canvas.steps.1": "Document where consumers are located.",
        "resource.location-canvas.steps.2": "Identify applicable regulations.",
        "resource.location-canvas.steps.3": "Document where data must reside.",
        "resource.location-canvas.steps.4": "Ensure the capability is accessible in all intended network regions.",
        "resource.location-canvas.steps.5": "Validate network performance across regions.",
        "resource.location-canvas.tips": "Collaborate with legal and compliance teams",
        "resource.location-canvas.tips.1": "Validate network performance across key regions",
        "resource.location-canvas.tips.2": "Proactively resolve location-based constraints",
        "resource.rest-canvas.title": "REST Canvas",
        "resource.rest-canvas.description": "Design APIs using RESTful principles, defining resources, verbs, and example requests and responses.",
        "resource.rest-canvas.outcomes": "Consistent RESTful API design",
        "resource.rest-canvas.outcomes.1": "Defined resources and their interactions",
        "resource.rest-canvas.outcomes.2": "Example requests and responses for clarity",
        "resource.rest-canvas.steps": "Identify key resources exposed by the API",
        "resource.rest-canvas.steps.1": "Define the structure of the API resource model",
        "resource.rest-canvas.steps.2": "Specify HTTP verbs used to interact with resources",
        "resource.rest-canvas.steps.3": "Provide example requests and responses for each verb",
        "resource.rest-canvas.tips": "Use standard HTTP methods (GET, POST, PUT, DELETE)",
        "resource.rest-canvas.tips.1": "Ensure resource URIs are intuitive and consistent",
        "resource.rest-canvas.tips.2": "Document error handling and response codes",
        "resource.capability-value-proposition-canvas.title": "Capability Value Proposition Canvas",
        "resource.capability-value-proposition-canvas.description": "A technology-agnostic canvas for mapping consumer tasks, gains, pains, and candidate reusable capabilities before selecting an implementation style.",
        "resource.capability-value-proposition-canvas.outcomes": "Clear reusable capability value proposition",
        "resource.capability-value-proposition-canvas.outcomes.1": "Consumer tasks, gains, and pains captured without assuming a technology",
        "resource.capability-value-proposition-canvas.outcomes.2": "Candidate reusable capabilities identified for architecture evaluation",
        "resource.capability-value-proposition-canvas.steps": "List the consumer tasks and outcomes the capability should support.",
        "resource.capability-value-proposition-canvas.steps.1": "Identify gain-enabling capability features.",
        "resource.capability-value-proposition-canvas.steps.2": "Identify pain-relieving capability features.",
        "resource.capability-value-proposition-canvas.steps.3": "Group the features into candidate reusable capabilities.",
        "resource.capability-value-proposition-canvas.tips": "Stay technology agnostic until the requirements indicate a suitable implementation style.",
        "resource.capability-value-proposition-canvas.tips.1": "Use this instead of the API Value Proposition Canvas when an API is not yet the selected implementation style.",
        "resource.capability-business-model-canvas.title": "Capability Business Model Canvas",
        "resource.capability-business-model-canvas.description": "A business model canvas for reusable capabilities, covering value, consumers, ownership, engagement, costs, and benefits without assuming an implementation style.",
        "resource.capability-business-model-canvas.outcomes": "Viable reusable capability operating model",
        "resource.capability-business-model-canvas.outcomes.1": "Ownership, consumers, channels, partners, and support needs clarified",
        "resource.capability-business-model-canvas.outcomes.2": "Costs and benefits visible before architecture commitment",
        "resource.capability-business-model-canvas.steps": "Summarize the capability value proposition.",
        "resource.capability-business-model-canvas.steps.1": "Identify consumer segments and engagement channels.",
        "resource.capability-business-model-canvas.steps.2": "Define key activities, resources, and partners.",
        "resource.capability-business-model-canvas.steps.3": "Capture costs and benefits.",
        "resource.capability-business-model-canvas.steps.4": "Clarify ownership, funding, support, and lifecycle expectations.",
        "resource.capability-business-model-canvas.steps.5": "Validate the model with consumers, producers, and governance stakeholders.",
        "resource.capability-business-model-canvas.tips": "Use this instead of the API Business Model Canvas while the implementation style remains open.",
        "resource.capability-business-model-canvas.tips.1": "Keep the focus on reusable capability viability, not a one-off connection.",
        "resource.consumer-experience-requirements-canvas.title": "Consumer Experience Requirements Canvas",
        "resource.consumer-experience-requirements-canvas.description": "A requirements canvas for consumer experience and non-functional needs that should guide the later architecture and implementation-style decision.",
        "resource.consumer-experience-requirements-canvas.outcomes": "Technology-agnostic consumer and service requirements",
        "resource.consumer-experience-requirements-canvas.outcomes.1": "Experience and non-functional needs captured before design starts",
        "resource.consumer-experience-requirements-canvas.outcomes.2": "Architecture implications documented for implementation-style selection",
        "resource.consumer-experience-requirements-canvas.steps": "Capture consumer goals and usage context.",
        "resource.consumer-experience-requirements-canvas.steps.1": "Document availability, timeliness, volume, performance, data quality, and consistency expectations.",
        "resource.consumer-experience-requirements-canvas.steps.2": "Document security, privacy, onboarding, change, observability, support, and recovery expectations.",
        "resource.consumer-experience-requirements-canvas.steps.3": "Summarize what the requirements imply for possible implementation styles.",
        "resource.consumer-experience-requirements-canvas.tips": "Use this as the bridge between capability value and architecture decision.",
        "resource.consumer-experience-requirements-canvas.tips.1": "Do not choose an API, event, file, stream, data product, direct integration, or hybrid style until the requirements indicate the fit.",
        "resource.integration-style-selection-guide.title": "Integration Style Selection Guide",
        "resource.integration-style-selection-guide.description": "Guidance for choosing between API, event, file, stream, data product, direct integration, or hybrid implementation styles based on requirements and constraints.",
        "resource.integration-style-selection-guide.outcomes": "Justified integration implementation style",
        "resource.integration-style-selection-guide.outcomes.1": "Tradeoffs documented across integration style options",
        "resource.integration-style-selection-guide.outcomes.2": "Selected style traceable to consumer, platform, data, and operational requirements",
        "resource.integration-style-selection-guide.steps": "Compare viable integration styles against latency, volume, coupling, data ownership, freshness, governance, and operability needs.",
        "resource.integration-style-selection-guide.steps.1": "Identify when API, event, file, stream, data product, direct integration, or hybrid approaches fit the use case.",
        "resource.integration-style-selection-guide.steps.2": "Document constraints, risks, and platform dependencies for the selected implementation style.",
        "resource.integration-style-selection-guide.steps.3": "Record why rejected alternatives were not selected.",
        "resource.integration-style-selection-guide.tips": "Use after requirements are explicit and before detailed contract design starts.",
        "resource.integration-style-selection-guide.tips.1": "Keep REST, event, GraphQL, file, stream, and data product resources as optional follow-on design resources.",
        "resource.process-workflow-design-guide.title": "Process Workflow Design Guide",
        "resource.process-workflow-design-guide.description": "Guidance for modeling the process steps, roles, handoffs, decision points, states, inputs, outputs, and exceptions that shape an automation workflow.",
        "resource.process-workflow-design-guide.outcomes": "Clear automation workflow design",
        "resource.process-workflow-design-guide.outcomes.1": "Process steps and handoffs documented before implementation",
        "resource.process-workflow-design-guide.outcomes.2": "Workflow states, inputs, outputs, and exception paths understood",
        "resource.process-workflow-design-guide.steps": "Map the current and target process flow, including human and system responsibilities.",
        "resource.process-workflow-design-guide.steps.1": "Identify workflow triggers, states, decisions, data inputs, outputs, and completion criteria.",
        "resource.process-workflow-design-guide.steps.2": "Document handoffs between users, systems, operations, and support roles.",
        "resource.process-workflow-design-guide.steps.3": "Confirm which steps should be automated and which require human judgment.",
        "resource.process-workflow-design-guide.tips": "Keep process design separate from API or integration contract design until the workflow is clear.",
        "resource.process-workflow-design-guide.tips.1": "Use this as the primary design resource for automation workflows.",
        "resource.decision-business-rules-guide.title": "Decision And Business Rules Guide",
        "resource.decision-business-rules-guide.description": "Guidance for capturing rules, thresholds, decisions, approvals, eligibility checks, and rule ownership for automation design.",
        "resource.decision-business-rules-guide.outcomes": "Explicit decisions and business rules",
        "resource.decision-business-rules-guide.outcomes.1": "Rules and thresholds documented with owners",
        "resource.decision-business-rules-guide.outcomes.2": "Automation decisions traceable to policy, process, or business intent",
        "resource.decision-business-rules-guide.steps": "List decisions the automation must make or support.",
        "resource.decision-business-rules-guide.steps.1": "Document rule conditions, thresholds, exceptions, approvals, and escalation points.",
        "resource.decision-business-rules-guide.steps.2": "Identify rule owners and change governance for each decision area.",
        "resource.decision-business-rules-guide.tips": "Separate stable business rules from configurable operational parameters.",
        "resource.decision-business-rules-guide.tips.1": "Use examples and edge cases to validate rule interpretation.",
        "resource.automation-trigger-handoff-exception-guide.title": "Automation Trigger, Handoff And Exception Guide",
        "resource.automation-trigger-handoff-exception-guide.description": "Guidance for defining automation triggers, human handoffs, exception handling, retries, compensating actions, and support escalation paths.",
        "resource.automation-trigger-handoff-exception-guide.outcomes": "Defined automation triggers and exception paths",
        "resource.automation-trigger-handoff-exception-guide.outcomes.1": "Human handoffs and support escalations are explicit",
        "resource.automation-trigger-handoff-exception-guide.outcomes.2": "Exceptions, retries, and compensating actions are designed before delivery",
        "resource.automation-trigger-handoff-exception-guide.steps": "Define the events, schedules, user actions, or system states that trigger the automation.",
        "resource.automation-trigger-handoff-exception-guide.steps.1": "Map handoffs from automation to users, operators, or support teams.",
        "resource.automation-trigger-handoff-exception-guide.steps.2": "Document exceptions, retry rules, timeout behavior, and fallback paths.",
        "resource.automation-trigger-handoff-exception-guide.steps.3": "Define alerts and escalation thresholds for failed or ambiguous automation outcomes.",
        "resource.automation-trigger-handoff-exception-guide.tips": "Design exception paths as first-class workflow behavior, not as afterthoughts.",
        "resource.automation-trigger-handoff-exception-guide.tips.1": "Include business and operations roles when validating handoffs.",
        "resource.automation-testing-guide.title": "Automation Testing Guide",
        "resource.automation-testing-guide.description": "Guidance for testing automated workflows, decisions, integrations, exceptions, rollback behavior, supervision, and user impact before release.",
        "resource.automation-testing-guide.outcomes": "Validated automation behavior",
        "resource.automation-testing-guide.outcomes.1": "Workflow, rule, exception, and integration tests defined",
        "resource.automation-testing-guide.outcomes.2": "Release confidence for automated and human-assisted paths",
        "resource.automation-testing-guide.steps": "Create tests for happy paths, edge cases, exceptions, retries, and handoffs.",
        "resource.automation-testing-guide.steps.1": "Validate business rules and decision outcomes with representative data.",
        "resource.automation-testing-guide.steps.2": "Test rollback, recovery, observability, and manual intervention paths.",
        "resource.automation-testing-guide.steps.3": "Include users and operators in acceptance testing where the automation changes work practices.",
        "resource.automation-testing-guide.tips": "Use production-like scenarios and data shapes without exposing sensitive data.",
        "resource.automation-testing-guide.tips.1": "Keep test evidence available for readiness review.",
        "resource.automation-operational-ownership-guide.title": "Automation Operational Ownership Guide",
        "resource.automation-operational-ownership-guide.description": "Guidance for defining ownership, runbooks, supervision, support, monitoring, change control, and continuous improvement responsibilities for automations.",
        "resource.automation-operational-ownership-guide.outcomes": "Clear automation operating model",
        "resource.automation-operational-ownership-guide.outcomes.1": "Ownership, support, and escalation responsibilities assigned",
        "resource.automation-operational-ownership-guide.outcomes.2": "Monitoring and change practices ready for live operation",
        "resource.automation-operational-ownership-guide.steps": "Define business, technical, and operational owners for the automation.",
        "resource.automation-operational-ownership-guide.steps.1": "Document runbooks, support paths, monitoring signals, service expectations, and escalation rules.",
        "resource.automation-operational-ownership-guide.steps.2": "Set change control and review practices for workflow, platform, and rule updates.",
        "resource.automation-operational-ownership-guide.tips": "Do not release an automation without a named owner for exceptions and ongoing improvement.",
        "resource.automation-operational-ownership-guide.tips.1": "Make supervision needs visible before delivery planning finishes.",
        "resource.automation-rollback-supervision-guide.title": "Automation Rollback And Supervision Guide",
        "resource.automation-rollback-supervision-guide.description": "Guidance for designing rollback, pause, manual override, monitoring, supervision, and recovery paths for automations.",
        "resource.automation-rollback-supervision-guide.outcomes": "Controlled automation recovery paths",
        "resource.automation-rollback-supervision-guide.outcomes.1": "Rollback, pause, and override behavior documented",
        "resource.automation-rollback-supervision-guide.outcomes.2": "Supervision needs and recovery responsibilities defined",
        "resource.automation-rollback-supervision-guide.steps": "Identify actions that must be reversible, paused, or manually overridden.",
        "resource.automation-rollback-supervision-guide.steps.1": "Define rollback, compensation, and recovery procedures for failed or incorrect automation outcomes.",
        "resource.automation-rollback-supervision-guide.steps.2": "Document supervision thresholds, alerts, and manual decision points.",
        "resource.automation-rollback-supervision-guide.steps.3": "Validate recovery procedures before release.",
        "resource.automation-rollback-supervision-guide.tips": "Treat rollback and supervision as part of the workflow design and delivery plan.",
        "resource.automation-rollback-supervision-guide.tips.1": "Use operational incidents and near misses to refine supervision criteria.",
        "resource.automation-readiness-checklist.title": "Automation Readiness Checklist",
        "resource.automation-readiness-checklist.description": "A checklist for validating automation workflow, controls, risk, compliance, human oversight, testing evidence, rollback, operations, and release readiness.",
        "resource.automation-readiness-checklist.outcomes": "Documented automation readiness",
        "resource.automation-readiness-checklist.outcomes.1": "Known readiness gaps and mitigations before release",
        "resource.automation-readiness-checklist.outcomes.2": "Evidence for quality, risk, compliance, oversight, and operational approval",
        "resource.automation-readiness-checklist.steps": "Review workflow design, business rules, controls, access, data handling, and exception paths.",
        "resource.automation-readiness-checklist.steps.1": "Verify testing evidence, rollback procedures, supervision model, and support readiness.",
        "resource.automation-readiness-checklist.steps.2": "Confirm ownership, runbooks, monitoring, change controls, and release approval.",
        "resource.automation-readiness-checklist.steps.3": "Record unresolved gaps, decisions, and accepted risks before release.",
        "resource.automation-readiness-checklist.tips": "Use before release and again after material workflow or rule changes.",
        "resource.automation-readiness-checklist.tips.1": "Make human oversight and exception handling explicit in the evidence.",
        "resource.automation-rollout-enablement-guide.title": "Automation Rollout And Enablement Guide",
        "resource.automation-rollout-enablement-guide.description": "Guidance for rolling out automations with user communication, onboarding, operating instructions, support paths, change management, and feedback loops.",
        "resource.automation-rollout-enablement-guide.outcomes": "Enabled automation users and operators",
        "resource.automation-rollout-enablement-guide.outcomes.1": "Rollout communication, onboarding, and support paths prepared",
        "resource.automation-rollout-enablement-guide.outcomes.2": "Users and operators understand how work changes after automation release",
        "resource.automation-rollout-enablement-guide.steps": "Define rollout audiences, timing, communication channels, and training needs.",
        "resource.automation-rollout-enablement-guide.steps.1": "Publish operating instructions, support paths, exception handling guidance, and escalation contacts.",
        "resource.automation-rollout-enablement-guide.steps.2": "Plan transition support for users, operators, and process owners.",
        "resource.automation-rollout-enablement-guide.steps.3": "Collect feedback after rollout and feed improvements into the backlog.",
        "resource.automation-rollout-enablement-guide.tips": "Use rollout language for automations instead of treating enablement as API publication.",
        "resource.automation-rollout-enablement-guide.tips.1": "Include both users affected by the process and operators responsible for the automation.",
        "resource.api-community-engagement-strategies.tips.2": "Use this resource when an API is the selected implementation style.",
        "resource.api-development-best-practices.tips.2": "Use this resource when an API is the selected implementation style.",
        "resource.api-metrics-and-analytics.tips.2": "Use this resource when an API is the selected implementation style.",
        "resource.api-testing-best-practices.tips.2": "Use this resource when an API is the selected implementation style.",
        "resource.apiops-CI-CD-for-apis.tips.2": "Use this resource when an API is the selected implementation style.",
        "resource.api-audit-checklist.tips.2": "Use this resource when an API is the selected implementation style.",
        "exit_criteria": "Exit criteria",
        "entry_criteria": "Entry criteria",
        "criterion.metrics-feedback-available": "Relevant market signals, feedback, or operational insights are available to guide this capability opportunity.",
        "criterion.business-goals-defined": "Business goals are defined.",
        "criterion.market-research-done": "Market research identifies capability opportunities.",
        "criterion.stakeholder-approval": "Relevant stakeholders agree this capability opportunity is worth exploring and prioritizing.",
        "criterion.api-opportunity-documented": "Capability opportunity is identified and documented.",
        "criterion.api-reusability": "The capability addresses a clear business need and is reusable by its intended consumers.",
        "criterion.hide-backend-discrepancies": "The selected interface provides an appropriate abstraction for consumers.",
        "criterion.value-prop-validated": "The capability value proposition has been validated with business and consumer stakeholders.",
        "criterion.consumer-segments-identified": "Consumer segments are identified.",
        "criterion.api-roadmap-defined": "A high-level implementation roadmap is defined.",
        "criterion.architecture-patterns-validated": "The chosen architecture, platform, and implementation style have been validated with the relevant architecture, security, and platform stakeholders.",
        "criterion.design-reflects-business-value": "The interface design and exposed capabilities trace back to business value and consumer needs.",
        "criterion.api-consistency": "The interface design follows agreed design standards and conventions.",
        "criterion.api-contract-tested": "The interface contract has been validated and tested against functional and non-functional requirements.",
        "criterion.automation-workflow-validated": "The workflow, rules, integrations, and relevant interface contracts have been validated and tested.",
        "criterion.api-description-available": "The interface and its capabilities are documented clearly enough for review, audit, and onboarding.",
        "criterion.audit-passed": "The solution passes quality, security, compliance, and readiness checks.",
        "criterion.audit-reports-shared": "Audit findings and remediation decisions are shared with the relevant stakeholders.",
        "criterion.api-ready-for-publishing": "The capability is ready to be published or released through the selected delivery mechanism.",
        "criterion.api-documentation-ready": "Consumer-facing documentation and onboarding materials are ready.",
        "criterion.consumer-support-ready": "Consumer onboarding, support, and communication processes are ready.",
        "criterion.legal-compliance-clear": "Legal, privacy, and compliance requirements for publishing or release are defined and understood.",
        "stakeholder.involvement.lead": "Lead",
        "stakeholder.involvement.core": "Core",
        "stakeholder.involvement.consulted": "Consulted",
        "stakeholder.business-owner.title": "Business Owner",
        "stakeholder.business-owner.description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
        "stakeholder.api-program-owner.title": "API Program Owner",
        "stakeholder.api-program-owner.description": "Coordinates API portfolio practices, organizational alignment, and long-term API capability development.",
        "stakeholder.api-product-owner.title": "API Product Owner",
        "stakeholder.api-product-owner.description": "Drives the API opportunity, prioritization, and product-level decisions across the lifecycle.",
        "stakeholder.capability-owner.title": "Capability Owner",
        "stakeholder.capability-owner.description": "Owns the capability vision, value, priorities, lifecycle, and reuse across consumers.",
        "stakeholder.domain-specialist.title": "Domain Expert",
        "stakeholder.domain-specialist.description": "Brings deep knowledge of the business domain, concepts, rules, and constraints the capability or interface must reflect.",
        "stakeholder.customer-specialist.title": "Customer or Partner Representative",
        "stakeholder.customer-specialist.description": "Contributes the business customer or partner perspective for the journey, value, and collaboration model.",
        "stakeholder.api-consumer-specialist.title": "API Consumer Representative",
        "stakeholder.api-consumer-specialist.description": "Represents the needs of developers, integrators, or other API consumers who use the API directly.",
        "stakeholder.platform-architect.title": "Platform Architect",
        "stakeholder.platform-architect.description": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
        "stakeholder.api-architect.title": "API Architect",
        "stakeholder.api-architect.description": "Owns API architecture, design principles, and interface contract quality.",
        "stakeholder.integration-architect.title": "Integration Architect",
        "stakeholder.integration-architect.description": "Designs integration approaches and implementation styles that connect the capability or API with other systems.",
        "stakeholder.platform-owner.title": "Platform Owner",
        "stakeholder.platform-owner.description": "Owns platform capabilities, roadmap, operational model, and service expectations.",
        "stakeholder.api-designer.title": "API Designer",
        "stakeholder.api-designer.description": "Shapes the interface contract, interaction model, consistency, and usability of the exposed capabilities.",
        "stakeholder.api-engineer.title": "Delivery Engineer",
        "stakeholder.api-engineer.description": "Owns implementation, automation, testing, and release flow concerns needed to deliver the capability, API, or automation reliably.",
        "stakeholder.automation-owner.title": "Automation Owner",
        "stakeholder.automation-owner.description": "Owns automation goals, business value, priorities, controls, and lifecycle outcomes.",
        "stakeholder.process-owner.title": "Process Owner",
        "stakeholder.process-owner.description": "Owns the business process being automated, including objectives, rules, outcomes, and improvement priorities.",
        "stakeholder.automation-engineer.title": "Automation Engineer",
        "stakeholder.automation-engineer.description": "Implements, tests, integrates, and maintains automation solutions and supporting workflows.",
        "stakeholder.security-specialist.title": "Security Specialist",
        "stakeholder.security-specialist.description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
        "stakeholder.compliance-specialist.title": "Compliance and Legal Specialist",
        "stakeholder.compliance-specialist.description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
        "stakeholder.governance-specialist.title": "API Governance Owner",
        "stakeholder.governance-specialist.description": "Represents review, audit, and organization-wide governance practices for API quality and conformity.",
        "stakeholder.api-devrel-specialist.title": "Documentation and DevRel Owner",
        "stakeholder.api-devrel-specialist.description": "Owns onboarding content, developer communication, and documentation quality for API consumers.",
        "stakeholder.operations-specialist.title": "Support and Operations Owner",
        "stakeholder.operations-specialist.description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
        "stakeholder.partner-specialist.title": "Partner or Vendor Manager",
        "stakeholder.partner-specialist.description": "Coordinates external partner, supplier, or vendor relationships that influence capability or API strategy and delivery.",
        "lines.title": "Metro Lines",
        "lines.description": "A collection of shared metro lines that guide reusable capability, API, integration, automation, and future data productization work.",
        "line.business-opportunities-line.title": "Business Opportunities Line",
        "line.business-opportunities-line.description": "Focuses on identifying and shaping business opportunities as reusable digital capabilities.",
        "line.platform-architecture-line.title": "Platform Architecture Line",
        "line.platform-architecture-line.description": "Covers architecture and platform decisions for reusable capabilities across implementation styles.",
        "line.api-design-line.title": "Design Line",
        "line.api-design-line.description": "Focuses on solution and interface design principles that can be used across APIs, integrations, automations, data products, and other implementation styles.",
        "line.delivery-line.title": "Delivery Line",
        "line.delivery-line.description": "Covers delivery and operational practices for reusable capabilities across implementation styles.",
        "line.publishing-and-adoption-line.title": "Publishing and Adoption Line",
        "line.publishing-and-adoption-line.description": "Focuses on publishing reusable capabilities and enabling adoption by consumers.",
        "line.operating-model-line.title": "Operating Model Line",
        "line.operating-model-line.description": "Covers the operating model for reusable capability management and governance."
      },
      "cycles": [
        {
          "id": "capability-productization-cycle",
          "slug": "capability-productization-cycle",
          "title": "Capability Productization Cycle",
          "description": "A cycle for turning business capabilities into reusable digital capabilities before selecting the implementation style.",
          "purpose": "Identify and productize reusable digital capabilities before choosing an API, event, file, stream, data product, AI-enabled service, direct integration, or hybrid implementation style.",
          "audiences": [],
          "audienceStakeholders": [
            {
              "id": "capability-owner",
              "sourceKey": "capability-owner",
              "sourceStakeholderId": "capability-owner",
              "title": "Capability Owner",
              "description": "Owns the capability vision, value, priorities, lifecycle, and reuse across consumers.",
              "involvement": "lead",
              "responsibilities": [
                {
                  "resourceId": "capabilityValuePropositionCanvas",
                  "resourceTitle": "Capability Value Proposition Canvas",
                  "canvasId": "capabilityValuePropositionCanvas",
                  "role": "suggested-answer-owner"
                },
                {
                  "resourceId": "capabilityBusinessModelCanvas",
                  "resourceTitle": "Capability Business Model Canvas",
                  "canvasId": "capabilityBusinessModelCanvas",
                  "role": "suggested-answer-owner"
                }
              ]
            },
            {
              "id": "business-owner",
              "sourceKey": "business-owner",
              "sourceStakeholderId": "business-owner",
              "title": "Business Owner",
              "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
              "involvement": "core",
              "responsibilities": [
                {
                  "resourceId": "customerJourneyCanvas",
                  "resourceTitle": "Customer Journey Canvas",
                  "canvasId": "customerJourneyCanvas",
                  "role": "suggested-answer-owner"
                }
              ]
            },
            {
              "id": "customer-specialist",
              "sourceKey": "customer-specialist",
              "sourceStakeholderId": "customer-specialist",
              "title": "Customer or Partner Representative",
              "description": "Contributes the business customer or partner perspective for the journey, value, and collaboration model.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "domain-specialist",
              "sourceKey": "domain-specialist",
              "sourceStakeholderId": "domain-specialist",
              "title": "Domain Expert",
              "description": "Brings deep knowledge of the business domain, concepts, rules, and constraints the capability or interface must reflect.",
              "involvement": "core",
              "responsibilities": [
                {
                  "resourceId": "domainCanvas",
                  "resourceTitle": "Domain Canvas",
                  "canvasId": "domainCanvas",
                  "role": "suggested-answer-owner"
                }
              ]
            },
            {
              "id": "api-consumer-specialist",
              "sourceKey": "api-consumer-specialist",
              "sourceStakeholderId": "api-consumer-specialist",
              "title": "API Consumer Representative",
              "description": "Represents the needs of developers, integrators, or other API consumers who use the API directly.",
              "involvement": "core",
              "responsibilities": [
                {
                  "resourceId": "consumerExperienceRequirementsCanvas",
                  "resourceTitle": "Consumer Experience Requirements Canvas",
                  "canvasId": "consumerExperienceRequirementsCanvas",
                  "role": "suggested-answer-owner"
                }
              ]
            },
            {
              "id": "platform-architect",
              "sourceKey": "platform-architect",
              "sourceStakeholderId": "platform-architect",
              "title": "Platform Architect",
              "description": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
              "involvement": "lead",
              "responsibilities": [
                {
                  "resourceId": "locationsCanvas",
                  "resourceTitle": "Location Canvas",
                  "canvasId": "locationsCanvas",
                  "role": "suggested-answer-owner"
                }
              ]
            },
            {
              "id": "compliance-specialist",
              "sourceKey": "compliance-specialist",
              "sourceStakeholderId": "compliance-specialist",
              "title": "Compliance and Legal Specialist",
              "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "platform-owner",
              "sourceKey": "platform-owner",
              "sourceStakeholderId": "platform-owner",
              "title": "Platform Owner",
              "description": "Owns platform capabilities, roadmap, operational model, and service expectations.",
              "involvement": "core",
              "responsibilities": [
                {
                  "resourceId": "capacityCanvas",
                  "resourceTitle": "Capacity Canvas",
                  "canvasId": "capacityCanvas",
                  "role": "suggested-answer-owner"
                }
              ]
            },
            {
              "id": "security-specialist",
              "sourceKey": "security-specialist",
              "sourceStakeholderId": "security-specialist",
              "title": "Security Specialist",
              "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "api-designer",
              "sourceKey": "api-designer",
              "sourceStakeholderId": "api-designer",
              "title": "API Designer",
              "description": "Shapes the interface contract, interaction model, consistency, and usability of the exposed capabilities.",
              "involvement": "lead",
              "responsibilities": []
            },
            {
              "id": "api-engineer",
              "sourceKey": "api-engineer",
              "sourceStakeholderId": "api-engineer",
              "title": "Delivery Engineer",
              "description": "Owns implementation, automation, testing, and release flow concerns needed to deliver the capability, API, or automation reliably.",
              "involvement": "lead",
              "responsibilities": []
            },
            {
              "id": "operations-specialist",
              "sourceKey": "operations-specialist",
              "sourceStakeholderId": "operations-specialist",
              "title": "Support and Operations Owner",
              "description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "governance-specialist",
              "sourceKey": "governance-specialist",
              "sourceStakeholderId": "governance-specialist",
              "title": "API Governance Owner",
              "description": "Represents review, audit, and organization-wide governance practices for API quality and conformity.",
              "involvement": "lead",
              "responsibilities": []
            },
            {
              "id": "api-devrel-specialist",
              "sourceKey": "api-devrel-specialist",
              "sourceStakeholderId": "api-devrel-specialist",
              "title": "Documentation and DevRel Owner",
              "description": "Owns onboarding content, developer communication, and documentation quality for API consumers.",
              "involvement": "core",
              "responsibilities": []
            }
          ],
          "entryCriteria": [
            "business-goals-defined",
            "stakeholder-approval"
          ],
          "exitCriteria": [
            "value-prop-validated",
            "architecture-patterns-validated",
            "audit-passed"
          ],
          "entryCriteriaDetails": [
            {
              "id": "business-goals-defined",
              "title": "Business goals are defined.",
              "description": "Business goals are defined."
            },
            {
              "id": "stakeholder-approval",
              "title": "Relevant stakeholders agree this capability opportunity is worth exploring and prioritizing.",
              "description": "Relevant stakeholders agree this API opportunity is worth exploring and prioritizing."
            }
          ],
          "exitCriteriaDetails": [
            {
              "id": "value-prop-validated",
              "title": "The capability value proposition has been validated with business and consumer stakeholders.",
              "description": "The API value proposition has been reviewed and validated with the relevant business and consumer stakeholders."
            },
            {
              "id": "architecture-patterns-validated",
              "title": "The chosen architecture, platform, and implementation style have been validated with the relevant architecture, security, and platform stakeholders.",
              "description": "The chosen API architecture and platform patterns have been validated with the relevant architecture, security, and platform stakeholders."
            },
            {
              "id": "audit-passed",
              "title": "The solution passes quality, security, compliance, and readiness checks.",
              "description": "The API passes compliance, security, and audit checks."
            }
          ],
          "questionnaireResources": [
            {
              "stationId": "api-product-strategy",
              "stationTitle": "Capability Strategy",
              "resourceId": "capabilityValuePropositionCanvas",
              "resourceTitle": "Capability Value Proposition Canvas",
              "canvasId": "capabilityValuePropositionCanvas",
              "suggestedAnswerOwner": {
                "id": "capability-owner",
                "sourceKey": "capability-owner",
                "sourceStakeholderId": "capability-owner",
                "title": "Capability Owner",
                "description": "Owns the capability vision, value, priorities, lifecycle, and reuse across consumers.",
                "involvement": "lead",
                "responsibilities": [
                  {
                    "resourceId": "capabilityValuePropositionCanvas",
                    "resourceTitle": "Capability Value Proposition Canvas",
                    "canvasId": "capabilityValuePropositionCanvas",
                    "role": "suggested-answer-owner"
                  },
                  {
                    "resourceId": "capabilityBusinessModelCanvas",
                    "resourceTitle": "Capability Business Model Canvas",
                    "canvasId": "capabilityBusinessModelCanvas",
                    "role": "suggested-answer-owner"
                  }
                ]
              }
            },
            {
              "stationId": "api-product-strategy",
              "stationTitle": "Capability Strategy",
              "resourceId": "capabilityBusinessModelCanvas",
              "resourceTitle": "Capability Business Model Canvas",
              "canvasId": "capabilityBusinessModelCanvas",
              "suggestedAnswerOwner": {
                "id": "capability-owner",
                "sourceKey": "capability-owner",
                "sourceStakeholderId": "capability-owner",
                "title": "Capability Owner",
                "description": "Owns the capability vision, value, priorities, lifecycle, and reuse across consumers.",
                "involvement": "lead",
                "responsibilities": [
                  {
                    "resourceId": "capabilityValuePropositionCanvas",
                    "resourceTitle": "Capability Value Proposition Canvas",
                    "canvasId": "capabilityValuePropositionCanvas",
                    "role": "suggested-answer-owner"
                  },
                  {
                    "resourceId": "capabilityBusinessModelCanvas",
                    "resourceTitle": "Capability Business Model Canvas",
                    "canvasId": "capabilityBusinessModelCanvas",
                    "role": "suggested-answer-owner"
                  }
                ]
              }
            },
            {
              "stationId": "api-product-strategy",
              "stationTitle": "Capability Strategy",
              "resourceId": "customerJourneyCanvas",
              "resourceTitle": "Customer Journey Canvas",
              "canvasId": "customerJourneyCanvas",
              "suggestedAnswerOwner": {
                "id": "business-owner",
                "sourceKey": "business-owner",
                "sourceStakeholderId": "business-owner",
                "title": "Business Owner",
                "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
                "involvement": "core",
                "responsibilities": [
                  {
                    "resourceId": "customerJourneyCanvas",
                    "resourceTitle": "Customer Journey Canvas",
                    "canvasId": "customerJourneyCanvas",
                    "role": "suggested-answer-owner"
                  }
                ]
              }
            },
            {
              "stationId": "api-product-strategy",
              "stationTitle": "Capability Strategy",
              "resourceId": "domainCanvas",
              "resourceTitle": "Domain Canvas",
              "canvasId": "domainCanvas",
              "suggestedAnswerOwner": {
                "id": "domain-specialist",
                "sourceKey": "domain-specialist",
                "sourceStakeholderId": "domain-specialist",
                "title": "Domain Expert",
                "description": "Brings deep knowledge of the business domain, concepts, rules, and constraints the capability or interface must reflect.",
                "involvement": "core",
                "responsibilities": [
                  {
                    "resourceId": "domainCanvas",
                    "resourceTitle": "Domain Canvas",
                    "canvasId": "domainCanvas",
                    "role": "suggested-answer-owner"
                  }
                ]
              }
            },
            {
              "stationId": "api-consumer-experience",
              "stationTitle": "Consumer Requirements & Onboarding",
              "resourceId": "consumerExperienceRequirementsCanvas",
              "resourceTitle": "Consumer Experience Requirements Canvas",
              "canvasId": "consumerExperienceRequirementsCanvas",
              "suggestedAnswerOwner": {
                "id": "api-consumer-specialist",
                "sourceKey": "api-consumer-specialist",
                "sourceStakeholderId": "api-consumer-specialist",
                "title": "API Consumer Representative",
                "description": "Represents the needs of developers, integrators, or other API consumers who use the API directly.",
                "involvement": "core",
                "responsibilities": [
                  {
                    "resourceId": "consumerExperienceRequirementsCanvas",
                    "resourceTitle": "Consumer Experience Requirements Canvas",
                    "canvasId": "consumerExperienceRequirementsCanvas",
                    "role": "suggested-answer-owner"
                  }
                ]
              }
            },
            {
              "stationId": "api-platform-architecture",
              "stationTitle": "Architecture & Platform Decisions",
              "resourceId": "locationsCanvas",
              "resourceTitle": "Location Canvas",
              "canvasId": "locationsCanvas",
              "suggestedAnswerOwner": {
                "id": "platform-architect",
                "sourceKey": "platform-architect",
                "sourceStakeholderId": "platform-architect",
                "title": "Platform Architect",
                "description": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
                "involvement": "lead",
                "responsibilities": [
                  {
                    "resourceId": "locationsCanvas",
                    "resourceTitle": "Location Canvas",
                    "canvasId": "locationsCanvas",
                    "role": "suggested-answer-owner"
                  }
                ]
              }
            },
            {
              "stationId": "api-platform-architecture",
              "stationTitle": "Architecture & Platform Decisions",
              "resourceId": "businessImpactCanvas",
              "resourceTitle": "Business Impact Canvas",
              "canvasId": "businessImpactCanvas",
              "suggestedAnswerOwner": {
                "id": "capability-owner",
                "sourceKey": "capability-owner",
                "sourceStakeholderId": "capability-owner",
                "title": "Capability Owner",
                "description": "Owns the capability vision, value, priorities, lifecycle, and reuse across consumers.",
                "involvement": "core",
                "responsibilities": [
                  {
                    "resourceId": "businessImpactCanvas",
                    "resourceTitle": "Business Impact Canvas",
                    "canvasId": "businessImpactCanvas",
                    "role": "suggested-answer-owner"
                  }
                ]
              }
            },
            {
              "stationId": "api-platform-architecture",
              "stationTitle": "Architecture & Platform Decisions",
              "resourceId": "capacityCanvas",
              "resourceTitle": "Capacity Canvas",
              "canvasId": "capacityCanvas",
              "suggestedAnswerOwner": {
                "id": "platform-owner",
                "sourceKey": "platform-owner",
                "sourceStakeholderId": "platform-owner",
                "title": "Platform Owner",
                "description": "Owns platform capabilities, roadmap, operational model, and service expectations.",
                "involvement": "core",
                "responsibilities": [
                  {
                    "resourceId": "capacityCanvas",
                    "resourceTitle": "Capacity Canvas",
                    "canvasId": "capacityCanvas",
                    "role": "suggested-answer-owner"
                  }
                ]
              }
            }
          ],
          "stations": [
            {
              "index": 1,
              "id": "api-product-strategy",
              "slug": "method/api-product-strategy",
              "icon": "strategy-outline",
              "title": "Capability Strategy",
              "description": "Frame the business need as a reusable capability with clear value, consumers, ownership, and business goals before selecting the implementation style.",
              "whyItMatters": "Integration and API work often jumps too quickly to a technical pattern. This station keeps the team focused on the business journey, domain meaning, value, reuse potential, ownership, and viability before selecting APIs, events, files, streams, data products, or direct integration.",
              "applyInWork": "Use shared journey, domain, value proposition, and business model canvases to gather technology-agnostic requirements and decide whether the capability should be reusable.",
              "outcomes": [
                "A technology-agnostic capability opportunity statement",
                "Shared understanding of consumers, producers, domain concepts, and reuse potential",
                "A capability value proposition and business model before architecture selection"
              ],
              "steps": [
                {
                  "text": "Map the customer or partner journey that creates the capability need and reveals tasks, pains, gains, inputs, outputs, and decision points.",
                  "resourceId": "customerJourneyCanvas",
                  "resourceTitle": "Customer Journey Canvas",
                  "canvasId": "customerJourneyCanvas"
                },
                {
                  "text": "Define the core entities, attributes, relationships, ownership, and business rules that the capability must respect.",
                  "resourceId": "domainCanvas",
                  "resourceTitle": "Domain Canvas",
                  "canvasId": "domainCanvas"
                },
                {
                  "text": "Use the Capability Value Proposition Canvas to capture consumer tasks, gains, pains, and reusable capability features without naming the delivery technology too early.",
                  "resourceId": "apiValuePropositionCanvas",
                  "resourceTitle": "API Value Proposition Canvas",
                  "canvasId": "apiValuePropositionCanvas"
                },
                {
                  "text": "Use the Capability Business Model Canvas to clarify ownership, partners, channels, costs, benefits, support, and lifecycle expectations for the reusable capability.",
                  "resourceId": "apiBusinessModelCanvas",
                  "resourceTitle": "API Business Model Canvas",
                  "canvasId": "apiBusinessModelCanvas"
                }
              ],
              "questions": [
                "Map the customer or partner journey that creates the capability need and reveals tasks, pains, gains, inputs, outputs, and decision points.",
                "Define the core entities, attributes, relationships, ownership, and business rules that the capability must respect.",
                "Use the Capability Value Proposition Canvas to capture consumer tasks, gains, pains, and reusable capability features without naming the delivery technology too early.",
                "Use the Capability Business Model Canvas to clarify ownership, partners, channels, costs, benefits, support, and lifecycle expectations for the reusable capability.",
                "Use shared journey, domain, value proposition, and business model canvases to gather technology-agnostic requirements and decide whether the capability should be reusable.",
                "Integration and API work often jumps too quickly to a technical pattern. This station keeps the team focused on the business journey, domain meaning, value, reuse potential, ownership, and viability before selecting APIs, events, files, streams, data products, or direct integration."
              ],
              "criteria": [
                "metrics-feedback-available",
                "business-goals-defined",
                "market-research-done",
                "stakeholder-approval"
              ],
              "criteriaDetails": [
                {
                  "id": "metrics-feedback-available",
                  "title": "Relevant market signals, feedback, or operational insights are available to guide this capability opportunity.",
                  "description": "Relevant market signals, feedback, or operational insights are available to guide this API opportunity."
                },
                {
                  "id": "business-goals-defined",
                  "title": "Business goals are defined.",
                  "description": "Business goals are defined."
                },
                {
                  "id": "market-research-done",
                  "title": "Market research identifies capability opportunities.",
                  "description": "Market research identifies API opportunities."
                },
                {
                  "id": "stakeholder-approval",
                  "title": "Relevant stakeholders agree this capability opportunity is worth exploring and prioritizing.",
                  "description": "Relevant stakeholders agree this API opportunity is worth exploring and prioritizing."
                }
              ],
              "baseTitle": "Strategy",
              "group": "Capability Lifecycle Core Stations",
              "lifecycleStage": "strategy",
              "stakeholders": [
                {
                  "id": "capability-owner",
                  "sourceKey": "capability-owner",
                  "sourceStakeholderId": "capability-owner",
                  "title": "Capability Owner",
                  "description": "Owns the capability vision, value, priorities, lifecycle, and reuse across consumers.",
                  "involvement": "lead",
                  "responsibilities": [
                    {
                      "resourceId": "capabilityValuePropositionCanvas",
                      "resourceTitle": "Capability Value Proposition Canvas",
                      "canvasId": "capabilityValuePropositionCanvas",
                      "role": "suggested-answer-owner"
                    },
                    {
                      "resourceId": "capabilityBusinessModelCanvas",
                      "resourceTitle": "Capability Business Model Canvas",
                      "canvasId": "capabilityBusinessModelCanvas",
                      "role": "suggested-answer-owner"
                    }
                  ]
                },
                {
                  "id": "business-owner",
                  "sourceKey": "business-owner",
                  "sourceStakeholderId": "business-owner",
                  "title": "Business Owner",
                  "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
                  "involvement": "core",
                  "responsibilities": [
                    {
                      "resourceId": "customerJourneyCanvas",
                      "resourceTitle": "Customer Journey Canvas",
                      "canvasId": "customerJourneyCanvas",
                      "role": "suggested-answer-owner"
                    }
                  ]
                },
                {
                  "id": "customer-specialist",
                  "sourceKey": "customer-specialist",
                  "sourceStakeholderId": "customer-specialist",
                  "title": "Customer or Partner Representative",
                  "description": "Contributes the business customer or partner perspective for the journey, value, and collaboration model.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "domain-specialist",
                  "sourceKey": "domain-specialist",
                  "sourceStakeholderId": "domain-specialist",
                  "title": "Domain Expert",
                  "description": "Brings deep knowledge of the business domain, concepts, rules, and constraints the capability or interface must reflect.",
                  "involvement": "core",
                  "responsibilities": [
                    {
                      "resourceId": "domainCanvas",
                      "resourceTitle": "Domain Canvas",
                      "canvasId": "domainCanvas",
                      "role": "suggested-answer-owner"
                    }
                  ]
                },
                {
                  "id": "api-program-owner",
                  "sourceKey": "api-program-owner",
                  "sourceStakeholderId": "api-program-owner",
                  "title": "API Program Owner",
                  "description": "Coordinates API portfolio practices, organizational alignment, and long-term API capability development.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "compliance-specialist",
                  "sourceKey": "compliance-specialist",
                  "sourceStakeholderId": "compliance-specialist",
                  "title": "Compliance and Legal Specialist",
                  "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "platform-architect",
                  "sourceKey": "platform-architect",
                  "sourceStakeholderId": "platform-architect",
                  "title": "Platform Architect",
                  "description": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
                  "involvement": "consulted",
                  "responsibilities": []
                }
              ],
              "resources": [
                {
                  "id": "customerJourneyCanvas",
                  "slug": "resources/customer-journey-canvas",
                  "title": "Customer Journey Canvas",
                  "description": "Map customer, partner, or consumer journeys to identify needs, pain points, gains, inputs, outputs, and experience expectations.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 1,
                  "outcomes": [
                    "Shared understanding of the customer, partner, or consumer journey",
                    "Needs, pain points, gains, inputs, and outputs documented",
                    "Journey evidence available for capability, requirements, and architecture decisions"
                  ],
                  "steps": [
                    "Define customer persona",
                    "Identify triggers for the journey",
                    "Describe the journey's end",
                    "Map journey steps with inputs/outputs",
                    "Identify customer pains",
                    "Summarize customer gains",
                    "Define necessary inputs and resulting outputs",
                    "Define interactions and processing expectations for each step"
                  ],
                  "canvasId": "customerJourneyCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "domainCanvas",
                  "slug": "resources/domain-canvas",
                  "title": "Domain Canvas",
                  "description": "A modeling tool to define and communicate the key entities and relationships in your domain, ensuring semantic consistency across capabilities, integrations, APIs, data products, and services.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 152,
                  "outcomes": [
                    "Shared domain model and terminology",
                    "Core entities, relationships, rules, and ownership clarified",
                    "Semantic consistency across capabilities, integrations, APIs, data products, and services"
                  ],
                  "steps": [
                    "Define core entities, their attributes, and relationships to create a shared conceptual understanding across capabilities, integrations, APIs, data products, and services."
                  ],
                  "canvasId": "domainCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "capabilityValuePropositionCanvas",
                  "slug": "resources/capability-value-proposition-canvas",
                  "title": "Capability Value Proposition Canvas",
                  "description": "A technology-agnostic canvas for mapping consumer tasks, gains, pains, and candidate reusable capabilities before selecting an implementation style.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 2.1,
                  "outcomes": [
                    "Clear reusable capability value proposition",
                    "Consumer tasks, gains, and pains captured without assuming a technology",
                    "Candidate reusable capabilities identified for architecture evaluation"
                  ],
                  "steps": [
                    "List the consumer tasks and outcomes the capability should support.",
                    "Identify gain-enabling capability features.",
                    "Identify pain-relieving capability features.",
                    "Group the features into candidate reusable capabilities."
                  ],
                  "canvasId": "capabilityValuePropositionCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "capabilityBusinessModelCanvas",
                  "slug": "resources/capability-business-model-canvas",
                  "title": "Capability Business Model Canvas",
                  "description": "A business model canvas for reusable capabilities, covering value, consumers, ownership, engagement, costs, and benefits without assuming an implementation style.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 3.1,
                  "outcomes": [
                    "Viable reusable capability operating model",
                    "Ownership, consumers, channels, partners, and support needs clarified",
                    "Costs and benefits visible before architecture commitment"
                  ],
                  "steps": [
                    "Summarize the capability value proposition.",
                    "Identify consumer segments and engagement channels.",
                    "Define key activities, resources, and partners.",
                    "Capture costs and benefits.",
                    "Clarify ownership, funding, support, and lifecycle expectations.",
                    "Validate the model with consumers, producers, and governance stakeholders."
                  ],
                  "canvasId": "capabilityBusinessModelCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                }
              ],
              "evidence": [
                "design-artifact",
                "documentation",
                "research",
                "roadmap"
              ]
            },
            {
              "index": 2,
              "id": "api-consumer-experience",
              "slug": "method/api-consumer-experience",
              "icon": "deployed-code-account-outline",
              "title": "Consumer Requirements & Onboarding",
              "description": "Capture consumer requirements, onboarding needs, constraints, service expectations, and producer responsibilities.",
              "whyItMatters": "The right architecture depends on consumer goals, onboarding expectations, service levels, data quality needs, change tolerance, observability, support, and producer constraints.",
              "applyInWork": "Use consumer experience and onboarding guidance to make expectations explicit for both consumers and producers.",
              "outcomes": [
                "Documented consumer requirements and onboarding expectations",
                "Clear producer responsibilities and support expectations",
                "Architecture-relevant constraints ready for decision making",
                "Improved adoption through consumer empathy, standards, and producer clarity"
              ],
              "steps": [
                {
                  "text": "Use the Consumer Experience Requirements Canvas to capture consumer goals, availability, freshness, volume, performance, data quality, security, onboarding, change, observability, and recovery expectations.",
                  "resourceId": "apiValuePropositionCanvas",
                  "resourceTitle": "API Value Proposition Canvas",
                  "canvasId": "apiValuePropositionCanvas"
                },
                {
                  "text": "Use onboarding guidance to describe how consumers will find, request, test, get approved for, and start using the capability.",
                  "resourceId": "customerJourneyCanvas",
                  "resourceTitle": "Customer Journey Canvas",
                  "canvasId": "customerJourneyCanvas"
                },
                {
                  "text": "Use the resulting journey and requirements to improve onboarding, documentation, support, and feedback loops for capability consumers.",
                  "resourceId": "api-onboarding-best-practices",
                  "resourceTitle": "API Onboarding Best Practices",
                  "canvasId": null
                }
              ],
              "questions": [
                "Use the Consumer Experience Requirements Canvas to capture consumer goals, availability, freshness, volume, performance, data quality, security, onboarding, change, observability, and recovery expectations.",
                "Use onboarding guidance to describe how consumers will find, request, test, get approved for, and start using the capability.",
                "Use the resulting journey and requirements to improve onboarding, documentation, support, and feedback loops for capability consumers.",
                "Use consumer experience and onboarding guidance to make expectations explicit for both consumers and producers.",
                "The right architecture depends on consumer goals, onboarding expectations, service levels, data quality needs, change tolerance, observability, support, and producer constraints."
              ],
              "criteria": [
                "api-opportunity-documented",
                "api-reusability",
                "hide-backend-discrepancies",
                "value-prop-validated",
                "consumer-segments-identified",
                "api-roadmap-defined"
              ],
              "criteriaDetails": [
                {
                  "id": "api-opportunity-documented",
                  "title": "Capability opportunity is identified and documented.",
                  "description": "Individual API opportunities are identified and documented."
                },
                {
                  "id": "api-reusability",
                  "title": "The capability addresses a clear business need and is reusable by its intended consumers.",
                  "description": "The API meets a clear business need and is reusable for multiple API consumers."
                },
                {
                  "id": "hide-backend-discrepancies",
                  "title": "The selected interface provides an appropriate abstraction for consumers.",
                  "description": "The API is intended to shield consumers from backend complexity and inconsistencies."
                },
                {
                  "id": "value-prop-validated",
                  "title": "The capability value proposition has been validated with business and consumer stakeholders.",
                  "description": "The API value proposition has been reviewed and validated with the relevant business and consumer stakeholders."
                },
                {
                  "id": "consumer-segments-identified",
                  "title": "Consumer segments are identified.",
                  "description": "API consumer segments (internal and external) are identified."
                },
                {
                  "id": "api-roadmap-defined",
                  "title": "A high-level implementation roadmap is defined.",
                  "description": "High-level roadmaps for API development are established."
                }
              ],
              "baseTitle": "Consumer Requirements & Onboarding",
              "group": "Capability Lifecycle Core Stations",
              "lifecycleStage": "strategy",
              "stakeholders": [
                {
                  "id": "customer-specialist",
                  "sourceKey": "customer-specialist",
                  "sourceStakeholderId": "customer-specialist",
                  "title": "Customer or Partner Representative",
                  "description": "Contributes the business customer or partner perspective for the journey, value, and collaboration model.",
                  "involvement": "lead",
                  "responsibilities": []
                },
                {
                  "id": "api-consumer-specialist",
                  "sourceKey": "api-consumer-specialist",
                  "sourceStakeholderId": "api-consumer-specialist",
                  "title": "API Consumer Representative",
                  "description": "Represents the needs of developers, integrators, or other API consumers who use the API directly.",
                  "involvement": "core",
                  "responsibilities": [
                    {
                      "resourceId": "consumerExperienceRequirementsCanvas",
                      "resourceTitle": "Consumer Experience Requirements Canvas",
                      "canvasId": "consumerExperienceRequirementsCanvas",
                      "role": "suggested-answer-owner"
                    }
                  ]
                },
                {
                  "id": "capability-owner",
                  "sourceKey": "capability-owner",
                  "sourceStakeholderId": "capability-owner",
                  "title": "Capability Owner",
                  "description": "Owns the capability vision, value, priorities, lifecycle, and reuse across consumers.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "domain-specialist",
                  "sourceKey": "domain-specialist",
                  "sourceStakeholderId": "domain-specialist",
                  "title": "Domain Expert",
                  "description": "Brings deep knowledge of the business domain, concepts, rules, and constraints the capability or interface must reflect.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "business-owner",
                  "sourceKey": "business-owner",
                  "sourceStakeholderId": "business-owner",
                  "title": "Business Owner",
                  "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "api-devrel-specialist",
                  "sourceKey": "api-devrel-specialist",
                  "sourceStakeholderId": "api-devrel-specialist",
                  "title": "Documentation and DevRel Owner",
                  "description": "Owns onboarding content, developer communication, and documentation quality for API consumers.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "operations-specialist",
                  "sourceKey": "operations-specialist",
                  "sourceStakeholderId": "operations-specialist",
                  "title": "Support and Operations Owner",
                  "description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
                  "involvement": "consulted",
                  "responsibilities": []
                }
              ],
              "resources": [
                {
                  "id": "consumerExperienceRequirementsCanvas",
                  "slug": "resources/consumer-experience-requirements-canvas",
                  "title": "Consumer Experience Requirements Canvas",
                  "description": "A requirements canvas for consumer experience and non-functional needs that should guide the later architecture and implementation-style decision.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 3.2,
                  "outcomes": [
                    "Technology-agnostic consumer and service requirements",
                    "Experience and non-functional needs captured before design starts",
                    "Architecture implications documented for implementation-style selection"
                  ],
                  "steps": [
                    "Capture consumer goals and usage context.",
                    "Document availability, timeliness, volume, performance, data quality, and consistency expectations.",
                    "Document security, privacy, onboarding, change, observability, support, and recovery expectations.",
                    "Summarize what the requirements imply for possible implementation styles."
                  ],
                  "canvasId": "consumerExperienceRequirementsCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "api-onboarding-best-practices",
                  "slug": "resources/api-onboarding-best-practices",
                  "title": "API Onboarding Best Practices",
                  "description": "Best practices to streamline API consumer onboarding journeys with step-by-step registration, discovery, and first-call guidance.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 121,
                  "outcomes": [
                    "Shared understanding of the purpose and use of API Onboarding Best Practices",
                    "A consistent approach to applying API Onboarding Best Practices",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Define the API consumer journey from discovery to troubleshooting, identifying key touchpoints and pain points.",
                    "Develop onboarding processes and resources to help API consumers understand how to use APIs effectively.",
                    "Document how consumers find and use the API, including onboarding processes and registration."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                }
              ],
              "evidence": [
                "design-artifact",
                "documentation",
                "consumer-feedback"
              ]
            },
            {
              "index": 3,
              "id": "api-platform-architecture",
              "slug": "method/api-platform-architecture",
              "icon": "code-blocks-outline",
              "title": "Architecture & Platform Decisions",
              "description": "Use requirements and constraints to select the implementation style, architecture pattern, and enabling platform capabilities.",
              "whyItMatters": "Architecture choices should follow from evidence about business impact, locations, trust boundaries, capacity, latency, data ownership, consistency, operability, security, privacy, governance, and cost.",
              "applyInWork": "Compare viable architecture styles against the gathered requirements and document the selected pattern and rationale.",
              "outcomes": [
                "A justified architecture choice",
                "Documented risks, locations, capacity, security, privacy, and operability constraints",
                "Clear rationale for API, event, file, stream, data product, direct integration, or hybrid implementation style"
              ],
              "steps": [
                {
                  "text": "Use the Business Impact Canvas to identify availability, security, and data risks that influence architecture options.",
                  "resourceId": "businessImpactCanvas",
                  "resourceTitle": "Business Impact Canvas",
                  "canvasId": "businessImpactCanvas"
                },
                {
                  "text": "Use the Locations Canvas to capture geopolitical, regulatory, network, residency, and trust-boundary constraints.",
                  "resourceId": "locationsCanvas",
                  "resourceTitle": "Location Canvas",
                  "canvasId": "locationsCanvas"
                },
                {
                  "text": "Use the Capacity Canvas to capture current and future volumes, peaks, latency, caching, rate limiting, and scaling expectations.",
                  "resourceId": "capacityCanvas",
                  "resourceTitle": "Capacity Canvas",
                  "canvasId": "capacityCanvas"
                },
                {
                  "text": "Use metrics and analytics guidance to define how the chosen capability will be monitored and improved.",
                  "resourceId": "api-metrics-and-analytics",
                  "resourceTitle": "API Metrics And Analytics",
                  "canvasId": null
                }
              ],
              "questions": [
                "Use the Business Impact Canvas to identify availability, security, and data risks that influence architecture options.",
                "Use the Locations Canvas to capture geopolitical, regulatory, network, residency, and trust-boundary constraints.",
                "Use the Capacity Canvas to capture current and future volumes, peaks, latency, caching, rate limiting, and scaling expectations.",
                "Use metrics and analytics guidance to define how the chosen capability will be monitored and improved.",
                "Compare viable architecture styles against the gathered requirements and document the selected pattern and rationale.",
                "Architecture choices should follow from evidence about business impact, locations, trust boundaries, capacity, latency, data ownership, consistency, operability, security, privacy, governance, and cost."
              ],
              "criteria": [
                "api-reusability",
                "hide-backend-discrepancies",
                "value-prop-validated",
                "consumer-segments-identified",
                "api-roadmap-defined"
              ],
              "criteriaDetails": [
                {
                  "id": "api-reusability",
                  "title": "The capability addresses a clear business need and is reusable by its intended consumers.",
                  "description": "The API meets a clear business need and is reusable for multiple API consumers."
                },
                {
                  "id": "hide-backend-discrepancies",
                  "title": "The selected interface provides an appropriate abstraction for consumers.",
                  "description": "The API is intended to shield consumers from backend complexity and inconsistencies."
                },
                {
                  "id": "value-prop-validated",
                  "title": "The capability value proposition has been validated with business and consumer stakeholders.",
                  "description": "The API value proposition has been reviewed and validated with the relevant business and consumer stakeholders."
                },
                {
                  "id": "consumer-segments-identified",
                  "title": "Consumer segments are identified.",
                  "description": "API consumer segments (internal and external) are identified."
                },
                {
                  "id": "api-roadmap-defined",
                  "title": "A high-level implementation roadmap is defined.",
                  "description": "High-level roadmaps for API development are established."
                }
              ],
              "baseTitle": "Architecture & Platform Decisions",
              "group": "Capability Lifecycle Core Stations",
              "lifecycleStage": "architecture",
              "stakeholders": [
                {
                  "id": "platform-architect",
                  "sourceKey": "platform-architect",
                  "sourceStakeholderId": "platform-architect",
                  "title": "Platform Architect",
                  "description": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
                  "involvement": "lead",
                  "responsibilities": [
                    {
                      "resourceId": "locationsCanvas",
                      "resourceTitle": "Location Canvas",
                      "canvasId": "locationsCanvas",
                      "role": "suggested-answer-owner"
                    }
                  ]
                },
                {
                  "id": "capability-owner",
                  "sourceKey": "capability-owner",
                  "sourceStakeholderId": "capability-owner",
                  "title": "Capability Owner",
                  "description": "Owns the capability vision, value, priorities, lifecycle, and reuse across consumers.",
                  "involvement": "core",
                  "responsibilities": [
                    {
                      "resourceId": "businessImpactCanvas",
                      "resourceTitle": "Business Impact Canvas",
                      "canvasId": "businessImpactCanvas",
                      "role": "suggested-answer-owner"
                    }
                  ]
                },
                {
                  "id": "compliance-specialist",
                  "sourceKey": "compliance-specialist",
                  "sourceStakeholderId": "compliance-specialist",
                  "title": "Compliance and Legal Specialist",
                  "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "platform-owner",
                  "sourceKey": "platform-owner",
                  "sourceStakeholderId": "platform-owner",
                  "title": "Platform Owner",
                  "description": "Owns platform capabilities, roadmap, operational model, and service expectations.",
                  "involvement": "core",
                  "responsibilities": [
                    {
                      "resourceId": "capacityCanvas",
                      "resourceTitle": "Capacity Canvas",
                      "canvasId": "capacityCanvas",
                      "role": "suggested-answer-owner"
                    }
                  ]
                },
                {
                  "id": "security-specialist",
                  "sourceKey": "security-specialist",
                  "sourceStakeholderId": "security-specialist",
                  "title": "Security Specialist",
                  "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "api-product-owner",
                  "sourceKey": "api-product-owner",
                  "sourceStakeholderId": "api-product-owner",
                  "title": "API Product Owner",
                  "description": "Drives the API opportunity, prioritization, and product-level decisions across the lifecycle.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "business-owner",
                  "sourceKey": "business-owner",
                  "sourceStakeholderId": "business-owner",
                  "title": "Business Owner",
                  "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "integration-architect",
                  "sourceKey": "integration-architect",
                  "sourceStakeholderId": "integration-architect",
                  "title": "Integration Architect",
                  "description": "Designs integration approaches and implementation styles that connect the capability or API with other systems.",
                  "involvement": "consulted",
                  "responsibilities": []
                }
              ],
              "resources": [
                {
                  "id": "businessImpactCanvas",
                  "slug": "resources/business-impact-canvas",
                  "title": "Business Impact Canvas",
                  "description": "Identify business, availability, security, data, compliance, and operational risks that should shape architecture and platform decisions.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 4,
                  "outcomes": [
                    "Documented business and operational impact assessment",
                    "Prioritized risks and mitigation actions",
                    "Evidence for architecture and platform decisions"
                  ],
                  "steps": [
                    "Availability Risks: Identify risks and impacts.",
                    "Ways to Mitigate Availability Risks: Define mitigation measures.",
                    "Security Risks: Document security-related risks.",
                    "Ways to Mitigate Security Risks: Propose strategies to mitigate security risks.",
                    "Data Risks: Identify risks to data accuracy or availability.",
                    "Ways to Mitigate Data Risks: Plan strategies to address data risks."
                  ],
                  "canvasId": "businessImpactCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "locationsCanvas",
                  "slug": "resources/location-canvas",
                  "title": "Location Canvas",
                  "description": "Map consumer, producer, system, data, network, regulatory, and trust-boundary locations to ensure compliance and performance across regions.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 6,
                  "outcomes": [
                    "Documented location, residency, network, and regulatory requirements",
                    "Regional performance and accessibility constraints identified",
                    "Data residency, trust boundaries, and applicable regulations clarified"
                  ],
                  "steps": [
                    "Map locations of producers, source systems, platforms, and consumers.",
                    "Document where consumers are located.",
                    "Identify applicable regulations.",
                    "Document where data must reside.",
                    "Ensure the capability is accessible in all intended network regions.",
                    "Validate network performance across regions."
                  ],
                  "canvasId": "locationsCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "capacityCanvas",
                  "slug": "resources/capacity-canvas",
                  "title": "Capacity Canvas",
                  "description": "Plan capacity for current and future demand, including volumes, peaks, latency, availability, scaling, caching, and rate limits for the selected capability and implementation style.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 7,
                  "outcomes": [
                    "Capacity requirements aligned with expected business demand",
                    "Peak-load, availability, and growth assumptions documented",
                    "Scaling, caching, and rate-limiting decisions defined"
                  ],
                  "steps": [
                    "Document current business volumes",
                    "Forecast future consumption trends",
                    "Plan for peak load and availability requirements",
                    "Define caching and rate-limiting strategies",
                    "Propose scaling strategies"
                  ],
                  "canvasId": "capacityCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                }
              ],
              "evidence": [
                "architecture-decision",
                "documentation",
                "platform-config",
                "metrics"
              ]
            },
            {
              "index": 4,
              "id": "api-design",
              "slug": "method/api-design",
              "icon": "api",
              "title": "Solution & Interface Design",
              "description": "Design the interface contract and interaction model for the selected implementation style.",
              "whyItMatters": "Once the architecture pattern is known, the design must turn capability requirements into clear interface contracts, interactions, schemas, data rules, lifecycle expectations, and consumer obligations.",
              "applyInWork": "Select the design resources that fit the chosen implementation style and document the interface contract before implementation.",
              "outcomes": [
                "A validated interface contract for the selected implementation style",
                "Consistent interaction, data, event, file, workflow, or API contract decisions",
                "Design traceability back to capability and consumer requirements",
                "Designs aligned with domain models and interaction patterns"
              ],
              "steps": [
                {
                  "text": "Reuse the Domain Canvas to confirm business objects, terms, rules, and ownership before contract design.",
                  "resourceId": "domainCanvas",
                  "resourceTitle": "Domain Canvas",
                  "canvasId": "domainCanvas"
                },
                {
                  "text": "Use the Interaction Canvas to describe how consumers, systems, or users interact with the capability.",
                  "resourceId": "interactionCanvas",
                  "resourceTitle": "Interaction Canvas",
                  "canvasId": "interactionCanvas"
                },
                {
                  "text": "Use REST design resources when the selected interface is a REST API.",
                  "resourceId": "restCanvas",
                  "resourceTitle": "REST Canvas",
                  "canvasId": "restCanvas"
                },
                {
                  "text": "Use Event Canvas resources when the selected interface is event-driven.",
                  "resourceId": "eventCanvas",
                  "resourceTitle": "Event Canvas",
                  "canvasId": "eventCanvas"
                },
                {
                  "text": "Use GraphQL design resources when the selected interface is GraphQL.",
                  "resourceId": "graphqlCanvas",
                  "resourceTitle": "GraphQL Canvas",
                  "canvasId": "graphqlCanvas"
                },
                {
                  "text": "Use the design principles and style guidance to align design decisions with shared rules and enable consistent audit validation.",
                  "resourceId": "api-design-principles",
                  "resourceTitle": "API Design Principles",
                  "canvasId": null
                },
                {
                  "text": "Apply contract-first or design-first approaches to capture and validate the interface contract before implementation.",
                  "resourceId": "contract-first-design",
                  "resourceTitle": "Contract First Design",
                  "canvasId": null
                },
                {
                  "text": "Use the audit checklist to ensure the design meets functional and non-functional requirements, including security, performance, and compliance.",
                  "resourceId": "api-audit-checklist",
                  "resourceTitle": "API Audit Checklist",
                  "canvasId": null
                }
              ],
              "questions": [
                "Reuse the Domain Canvas to confirm business objects, terms, rules, and ownership before contract design.",
                "Use the Interaction Canvas to describe how consumers, systems, or users interact with the capability.",
                "Use REST design resources when the selected interface is a REST API.",
                "Use Event Canvas resources when the selected interface is event-driven.",
                "Use GraphQL design resources when the selected interface is GraphQL.",
                "Use the design principles and style guidance to align design decisions with shared rules and enable consistent audit validation.",
                "Apply contract-first or design-first approaches to capture and validate the interface contract before implementation.",
                "Use the audit checklist to ensure the design meets functional and non-functional requirements, including security, performance, and compliance.",
                "Select the design resources that fit the chosen implementation style and document the interface contract before implementation.",
                "Once the architecture pattern is known, the design must turn capability requirements into clear interface contracts, interactions, schemas, data rules, lifecycle expectations, and consumer obligations."
              ],
              "criteria": [
                "architecture-patterns-validated",
                "hide-backend-discrepancies",
                "design-reflects-business-value",
                "api-consistency"
              ],
              "criteriaDetails": [
                {
                  "id": "architecture-patterns-validated",
                  "title": "The chosen architecture, platform, and implementation style have been validated with the relevant architecture, security, and platform stakeholders.",
                  "description": "The chosen API architecture and platform patterns have been validated with the relevant architecture, security, and platform stakeholders."
                },
                {
                  "id": "hide-backend-discrepancies",
                  "title": "The selected interface provides an appropriate abstraction for consumers.",
                  "description": "The API is intended to shield consumers from backend complexity and inconsistencies."
                },
                {
                  "id": "design-reflects-business-value",
                  "title": "The interface design and exposed capabilities trace back to business value and consumer needs.",
                  "description": "The API design and exposed capabilities clearly trace back to business value and user needs."
                },
                {
                  "id": "api-consistency",
                  "title": "The interface design follows agreed design standards and conventions.",
                  "description": "The API design follows our shared API product and design conventions."
                }
              ],
              "baseTitle": "Solution & Interface Design",
              "group": "Capability Lifecycle Core Stations",
              "lifecycleStage": "design",
              "stakeholders": [
                {
                  "id": "api-designer",
                  "sourceKey": "api-designer",
                  "sourceStakeholderId": "api-designer",
                  "title": "API Designer",
                  "description": "Shapes the interface contract, interaction model, consistency, and usability of the exposed capabilities.",
                  "involvement": "lead",
                  "responsibilities": []
                },
                {
                  "id": "api-consumer-specialist",
                  "sourceKey": "api-consumer-specialist",
                  "sourceStakeholderId": "api-consumer-specialist",
                  "title": "API Consumer Representative",
                  "description": "Represents the needs of developers, integrators, or other API consumers who use the API directly.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "capability-owner",
                  "sourceKey": "capability-owner",
                  "sourceStakeholderId": "capability-owner",
                  "title": "Capability Owner",
                  "description": "Owns the capability vision, value, priorities, lifecycle, and reuse across consumers.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "domain-specialist",
                  "sourceKey": "domain-specialist",
                  "sourceStakeholderId": "domain-specialist",
                  "title": "Domain Expert",
                  "description": "Brings deep knowledge of the business domain, concepts, rules, and constraints the capability or interface must reflect.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "platform-architect",
                  "sourceKey": "platform-architect",
                  "sourceStakeholderId": "platform-architect",
                  "title": "Platform Architect",
                  "description": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "api-product-owner",
                  "sourceKey": "api-product-owner",
                  "sourceStakeholderId": "api-product-owner",
                  "title": "API Product Owner",
                  "description": "Drives the API opportunity, prioritization, and product-level decisions across the lifecycle.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "integration-architect",
                  "sourceKey": "integration-architect",
                  "sourceStakeholderId": "integration-architect",
                  "title": "Integration Architect",
                  "description": "Designs integration approaches and implementation styles that connect the capability or API with other systems.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "security-specialist",
                  "sourceKey": "security-specialist",
                  "sourceStakeholderId": "security-specialist",
                  "title": "Security Specialist",
                  "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
                  "involvement": "consulted",
                  "responsibilities": []
                }
              ],
              "resources": [
                {
                  "id": "domainCanvas",
                  "slug": "resources/domain-canvas",
                  "title": "Domain Canvas",
                  "description": "A modeling tool to define and communicate the key entities and relationships in your domain, ensuring semantic consistency across capabilities, integrations, APIs, data products, and services.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 152,
                  "outcomes": [
                    "Shared domain model and terminology",
                    "Core entities, relationships, rules, and ownership clarified",
                    "Semantic consistency across capabilities, integrations, APIs, data products, and services"
                  ],
                  "steps": [
                    "Define core entities, their attributes, and relationships to create a shared conceptual understanding across capabilities, integrations, APIs, data products, and services."
                  ],
                  "canvasId": "domainCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "interactionCanvas",
                  "slug": "resources/interaction-canvas",
                  "title": "Interaction Canvas",
                  "description": "Define interactions, workflows, inputs, outputs, commands, queries, events, and expected responses to ensure a consistent consumer experience.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 9,
                  "outcomes": [
                    "Defined interaction model for the selected capability",
                    "Inputs, outputs, commands, queries, events, and responses clarified",
                    "Validation rules and interaction expectations agreed"
                  ],
                  "steps": [
                    "Map interactions to user, consumer, or system tasks",
                    "Define access points, operations, commands, queries, or events for each interaction",
                    "Document inputs and outputs for each interaction.",
                    "Specify validation rules and constraints",
                    "Create interaction models for CRUD, query-driven, command-driven, and event-driven interactions"
                  ],
                  "canvasId": "interactionCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "contract-first-design",
                  "slug": "resources/contract-first-design",
                  "title": "Contract First Design",
                  "description": "A guideline advocating for API-first approaches using formal contracts (e.g., OpenAPI) to align stakeholders before development.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 146,
                  "outcomes": [
                    "Shared understanding of the purpose and use of Contract First Design",
                    "A consistent approach to applying Contract First Design",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Apply contract-first or design-first approaches to ensure API interface contracts are validated before implementation.",
                    "Define API interface contracts that outline the expectations, responsibilities, and usage guidelines for each API.",
                    "Use standardized formats (e.g., OpenAPI, AsyncAPI) to create machine-readable API interface contracts that are easy to share and validate."
                  ],
                  "canvasId": null,
                  "sourcePath": "src/snippets/api-contract-example.yaml",
                  "sourceUrl": null,
                  "contentMarkdown": "openapi: 3.0.3\r\ninfo:\r\n  title: Sample Catalog API\r\n  version: 1.0.0\r\n  description: |\r\n    Starter example for a read-only APIOps Cycles API.\r\n    This example keeps the contract audit-friendly and easy to extend.\r\nservers:\r\n  - url: /v1\r\n    description: Versioned API base path\r\ntags:\r\n  - name: catalog\r\n    description: Browse and search catalog items\r\npaths:\r\n  /items:\r\n    get:\r\n      tags: [catalog]\r\n      summary: List catalog items\r\n      description: Returns a paginated list of public catalog items.\r\n      operationId: listItems\r\n      parameters:\r\n        - $ref: \"#/components/parameters/searchTerm\"\r\n        - $ref: \"#/components/parameters/categoryId\"\r\n        - $ref: \"#/components/parameters/page\"\r\n        - $ref: \"#/components/parameters/pageSize\"\r\n      responses:\r\n        \"200\":\r\n          description: Item list\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemListResponse\"\r\n              examples:\r\n                default:\r\n                  value:\r\n                    data:\r\n                      - itemId: item-123\r\n                        slug: blue-widget\r\n                        name: Blue Widget\r\n                        status: published\r\n                    page:\r\n                      number: 1\r\n                      size: 20\r\n                      totalItems: 1\r\n        \"400\":\r\n          $ref: \"#/components/responses/BadRequest\"\r\n        \"429\":\r\n          $ref: \"#/components/responses/TooManyRequests\"\r\n  /items/{itemId}:\r\n    get:\r\n      tags: [catalog]\r\n      summary: Get item by id\r\n      description: Returns a single public catalog item by opaque identifier.\r\n      operationId: getItemById\r\n      parameters:\r\n        - $ref: \"#/components/parameters/itemId\"\r\n      responses:\r\n        \"200\":\r\n          description: Item details\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemDetail\"\r\n        \"400\":\r\n          $ref: \"#/components/responses/BadRequest\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\n  /items/by-slug/{slug}:\r\n    get:\r\n      tags: [catalog]\r\n      summary: Get item by slug\r\n      description: Returns a single item by public slug.\r\n      operationId: getItemBySlug\r\n      parameters:\r\n        - $ref: \"#/components/parameters/slug\"\r\n      responses:\r\n        \"200\":\r\n          description: Item details\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemDetail\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\n  /categories/{categoryId}/items:\r\n    get:\r\n      tags: [catalog]\r\n      summary: List items in category\r\n      description: Returns public items in a category.\r\n      operationId: listItemsByCategory\r\n      parameters:\r\n        - $ref: \"#/components/parameters/categoryId\"\r\n      responses:\r\n        \"200\":\r\n          description: Category item list\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemListResponse\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\ncomponents:\r\n  parameters:\r\n    itemId:\r\n      name: itemId\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9][a-z0-9-]{1,63}$\"\r\n      example: item-123\r\n    slug:\r\n      name: slug\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9]+(?:-[a-z0-9]+)*$\"\r\n      example: blue-widget\r\n    categoryId:\r\n      name: categoryId\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9][a-z0-9-]{1,63}$\"\r\n      example: home-goods\r\n    searchTerm:\r\n      name: searchTerm\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: string\r\n        minLength: 1\r\n      example: widget\r\n    page:\r\n      name: page\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: integer\r\n        minimum: 1\r\n        default: 1\r\n    pageSize:\r\n      name: pageSize\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: integer\r\n        minimum: 1\r\n        maximum: 100\r\n        default: 20\r\n  responses:\r\n    BadRequest:\r\n      description: Validation failed\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n          examples:\r\n            default:\r\n              value:\r\n                code: BAD_REQUEST\r\n                message: Invalid request\r\n    NotFound:\r\n      description: Resource not found\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n    TooManyRequests:\r\n      description: Rate limit exceeded\r\n      headers:\r\n        Retry-After:\r\n          schema:\r\n            type: integer\r\n          description: Seconds until the next allowed request.\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n  schemas:\r\n    ItemListResponse:\r\n      type: object\r\n      required: [data, page]\r\n      properties:\r\n        data:\r\n          type: array\r\n          items:\r\n            $ref: \"#/components/schemas/ItemSummary\"\r\n        page:\r\n          $ref: \"#/components/schemas/Page\"\r\n    ItemSummary:\r\n      type: object\r\n      required: [itemId, slug, name, status]\r\n      properties:\r\n        itemId:\r\n          type: string\r\n        slug:\r\n          type: string\r\n        name:\r\n          type: string\r\n        status:\r\n          type: string\r\n          enum: [published, hidden]\r\n    ItemDetail:\r\n      allOf:\r\n        - $ref: \"#/components/schemas/ItemSummary\"\r\n        - type: object\r\n          properties:\r\n            description:\r\n              type: string\r\n            categories:\r\n              type: array\r\n              items:\r\n                type: string\r\n            variants:\r\n              type: array\r\n              items:\r\n                $ref: \"#/components/schemas/Variant\"\r\n    Variant:\r\n      type: object\r\n      required: [variantId, sku, price, inventory]\r\n      properties:\r\n        variantId:\r\n          type: string\r\n        sku:\r\n          type: string\r\n        price:\r\n          $ref: \"#/components/schemas/Price\"\r\n        inventory:\r\n          $ref: \"#/components/schemas/Inventory\"\r\n    Price:\r\n      type: object\r\n      required: [amount, currency]\r\n      properties:\r\n        amount:\r\n          type: number\r\n          format: decimal\r\n        currency:\r\n          type: string\r\n          example: EUR\r\n    Inventory:\r\n      type: object\r\n      required: [available]\r\n      properties:\r\n        available:\r\n          type: integer\r\n          minimum: 0\r\n        reserved:\r\n          type: integer\r\n          minimum: 0\r\n        source:\r\n          type: string\r\n    Page:\r\n      type: object\r\n      required: [number, size, totalItems]\r\n      properties:\r\n        number:\r\n          type: integer\r\n        size:\r\n          type: integer\r\n        totalItems:\r\n          type: integer\r\n    ErrorResponse:\r\n      type: object\r\n      required: [code, message]\r\n      properties:\r\n        code:\r\n          type: string\r\n        message:\r\n          type: string\r\n",
                  "draft": true
                }
              ],
              "evidence": [
                "spec",
                "contract",
                "design-artifact",
                "documentation"
              ]
            },
            {
              "index": 5,
              "id": "api-delivery",
              "slug": "method/api-delivery",
              "icon": "code",
              "title": "Delivery & Operations",
              "description": "Build, test, deploy, and operate the capability using the selected implementation style and validated interface contract.",
              "whyItMatters": "A reusable capability needs reliable delivery and operations regardless of whether it becomes an API, event stream, file exchange, data product, or direct integration.",
              "applyInWork": "Apply delivery, testing, CI/CD, operations, and security guidance to the chosen implementation style.",
              "outcomes": [
                "A delivered capability aligned with the validated interface contract",
                "Automated testing, deployment, and environment controls",
                "Security, operations, and quality practices appropriate to the chosen pattern",
                "Traceable delivery and release controls"
              ],
              "steps": [
                {
                  "text": "Use development best practices to implement the validated interface contract with established frameworks, libraries, and team standards.",
                  "resourceId": "api-development-best-practices",
                  "resourceTitle": "API Development Best Practices",
                  "canvasId": null
                },
                {
                  "text": "Build the implementation from the validated interface contract using established frameworks, libraries, and team standards.",
                  "resourceId": "api-development-best-practices",
                  "resourceTitle": "API Development Best Practices",
                  "canvasId": null
                },
                {
                  "text": "Use testing guidance to verify functionality, data quality, compatibility, security, performance, resilience, and recovery expectations.",
                  "resourceId": "api-testing-best-practices",
                  "resourceTitle": "API Testing Best Practices",
                  "canvasId": null
                },
                {
                  "text": "Use CI/CD guidance to automate build, test, deployment, configuration, and traceability.",
                  "resourceId": "apiops-CI-CD-for-apis",
                  "resourceTitle": "APIOps CI/CD For APIs",
                  "canvasId": null
                },
                {
                  "text": "Use security guidance to protect data, access, credentials, and platform boundaries.",
                  "resourceId": "api-security-best-practices",
                  "resourceTitle": "API Security Best Practices",
                  "canvasId": null
                },
                {
                  "text": "Use the audit checklist to ensure the solution meets functional and non-functional requirements, including security, performance, and compliance.",
                  "resourceId": "api-audit-checklist",
                  "resourceTitle": "API Audit Checklist",
                  "canvasId": null
                }
              ],
              "questions": [
                "Use development best practices to implement the validated interface contract with established frameworks, libraries, and team standards.",
                "Build the implementation from the validated interface contract using established frameworks, libraries, and team standards.",
                "Use testing guidance to verify functionality, data quality, compatibility, security, performance, resilience, and recovery expectations.",
                "Use CI/CD guidance to automate build, test, deployment, configuration, and traceability.",
                "Use security guidance to protect data, access, credentials, and platform boundaries.",
                "Use the audit checklist to ensure the solution meets functional and non-functional requirements, including security, performance, and compliance.",
                "Apply delivery, testing, CI/CD, operations, and security guidance to the chosen implementation style.",
                "A reusable capability needs reliable delivery and operations regardless of whether it becomes an API, event stream, file exchange, data product, or direct integration."
              ],
              "criteria": [
                "architecture-patterns-validated",
                "hide-backend-discrepancies",
                "design-reflects-business-value",
                "api-consistency"
              ],
              "criteriaDetails": [
                {
                  "id": "architecture-patterns-validated",
                  "title": "The chosen architecture, platform, and implementation style have been validated with the relevant architecture, security, and platform stakeholders.",
                  "description": "The chosen API architecture and platform patterns have been validated with the relevant architecture, security, and platform stakeholders."
                },
                {
                  "id": "hide-backend-discrepancies",
                  "title": "The selected interface provides an appropriate abstraction for consumers.",
                  "description": "The API is intended to shield consumers from backend complexity and inconsistencies."
                },
                {
                  "id": "design-reflects-business-value",
                  "title": "The interface design and exposed capabilities trace back to business value and consumer needs.",
                  "description": "The API design and exposed capabilities clearly trace back to business value and user needs."
                },
                {
                  "id": "api-consistency",
                  "title": "The interface design follows agreed design standards and conventions.",
                  "description": "The API design follows our shared API product and design conventions."
                }
              ],
              "baseTitle": "Delivery & Operations",
              "group": "Capability Lifecycle Core Stations",
              "lifecycleStage": "delivery",
              "stakeholders": [
                {
                  "id": "api-engineer",
                  "sourceKey": "api-engineer",
                  "sourceStakeholderId": "api-engineer",
                  "title": "Delivery Engineer",
                  "description": "Owns implementation, automation, testing, and release flow concerns needed to deliver the capability, API, or automation reliably.",
                  "involvement": "lead",
                  "responsibilities": []
                },
                {
                  "id": "platform-architect",
                  "sourceKey": "platform-architect",
                  "sourceStakeholderId": "platform-architect",
                  "title": "Platform Architect",
                  "description": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "security-specialist",
                  "sourceKey": "security-specialist",
                  "sourceStakeholderId": "security-specialist",
                  "title": "Security Specialist",
                  "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "operations-specialist",
                  "sourceKey": "operations-specialist",
                  "sourceStakeholderId": "operations-specialist",
                  "title": "Support and Operations Owner",
                  "description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "api-designer",
                  "sourceKey": "api-designer",
                  "sourceStakeholderId": "api-designer",
                  "title": "API Designer",
                  "description": "Shapes the interface contract, interaction model, consistency, and usability of the exposed capabilities.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "capability-owner",
                  "sourceKey": "capability-owner",
                  "sourceStakeholderId": "capability-owner",
                  "title": "Capability Owner",
                  "description": "Owns the capability vision, value, priorities, lifecycle, and reuse across consumers.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "compliance-specialist",
                  "sourceKey": "compliance-specialist",
                  "sourceStakeholderId": "compliance-specialist",
                  "title": "Compliance and Legal Specialist",
                  "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
                  "involvement": "consulted",
                  "responsibilities": []
                }
              ],
              "resources": [
                {
                  "id": "api-development-best-practices",
                  "slug": "resources/api-development-best-practices",
                  "title": "API Development Best Practices",
                  "description": "Implementation guidance for turning a validated API interface contract into a consistent, maintainable API codebase using standard libraries, reusable patterns, and aligned development workflows.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 112,
                  "outcomes": [
                    "Shared understanding of the purpose and use of API Development Best Practices",
                    "A consistent approach to applying API Development Best Practices",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Apply these practices to the validated API interface contract and implementation plan before coding begins.",
                    "Use established frameworks, libraries, and coding standards to implement the contract consistently and maintainably."
                  ],
                  "canvasId": null,
                  "sourcePath": "src/snippets/api-design-principles-guidance.md",
                  "sourceUrl": null,
                  "contentMarkdown": "## How to start the API Delivery work based on the previous phases (\"stations\")\r\n\r\nUse this guidance at the start of `API Delivery` after the API contract (e.g. OpenAPI) and the key outputs from earlier stations have been reviewed and accepted.\r\n\r\nThe goal is not to invent implementation in isolation. The goal is to turn the agreed outputs from earlier stations into concrete code structure, validation rules, runtime behavior, and API product delivery decisions.\r\n\r\n---\r\n\r\n### 1. Start From The Validated Contract\r\n\r\n- Treat the validated API contract as the main reference point for implementation decisions.\r\n- Keep the contract and implementation aligned throughout the API product delivery.\r\n- Use the contract to drive request validation, response mapping, documentation, and tests.\r\n\r\n---\r\n\r\n### 2. Use Domain Outputs To Preserve Business Meaning\r\n\r\n- Use the `Domain Canvas` outputs to guide naming, how the implementation is split into clear business responsibilities, and how different backend systems are connected without exposing their differences.\r\n- Preserve the validated meanings of entities, attributes, statuses, and source-of-truth rules.\r\n- Avoid leaking backend-specific models or inconsistencies into the public API.\r\n\r\n---\r\n\r\n### 3. Use Journey Outputs To Preserve Critical Flows\r\n\r\n- Use the `Customer Journey Canvas` outputs to identify which user flows are most important to support first.\r\n- Use the `API Consumer Experience` outputs to keep the API understandable, predictable, and easy to integrate.\r\n- Let the agreed journey priorities decide which implementation paths need the highest reliability, lowest latency, clearest errors, and strongest operational focus.\r\n\r\n---\r\n\r\n### 4. Use Value Proposition Outputs To Preserve Consumer Value\r\n\r\n- Use the `API Value Proposition Canvas` outputs to keep the implementation focused on the agreed pains, gains, and API features.\r\n- Preserve the field meanings, behavior, and promises that made the API valuable in the earlier stations.\r\n- Ensure error handling, freshness, and naming support both the intended developer experience and the business use case.\r\n\r\n---\r\n\r\n### 5. Use Architecture Outputs To Shape Runtime Decisions\r\n\r\n- Use the `Business Impact Canvas` outputs to guide resilience, timeout, fallback, and degradation decisions.\r\n- Use the `Locations Canvas` outputs to guide network boundaries, trust boundaries, access paths, and deployment constraints.\r\n- Use the `Capacity Canvas` outputs to guide rate limits, caching, scaling, and peak-load behavior.\r\n- Use the `API Metrics And Analytics` guidance to decide what must be observed from the first implementation onward.\r\n\r\n---\r\n\r\n### 6. Use Interaction And Protocol Design Outputs To Shape Code Structure\r\n\r\n- Use the `Interaction Canvas` outputs to avoid implementing unsupported interaction styles too early.\r\n- Use the `REST`, `Event`, or `GraphQL` design outputs to shape protocol-specific request, response, and validation behavior.\r\n- Reflect the selected interaction style clearly in code structure, responsibilities, and testing strategy.\r\n\r\n---\r\n\r\n### 7. Use Audit Outputs To Improve Delivery Before Coding Goes Too Far\r\n\r\n- Use the audit findings to remove ambiguity before implementation spreads across the codebase.\r\n- Fix unclear request rules, missing validation, weak error contracts, and operational gaps early.\r\n- Treat audit as a design-improvement loop before production, not only as a final decision gate.\r\n\r\n---\r\n\r\n### 8. Apply The Guidance, Then Summarize\r\n\r\n- Apply this guidance to the current API and implementation plan.\r\n- Summarize the implications for code structure, request validation, source integration, security, monitoring and alerts, and testing.\r\n- Do not create a separate delivery artifact unless the team or user specifically needs one.\r\n",
                  "draft": true
                },
                {
                  "id": "api-testing-best-practices",
                  "slug": "resources/api-testing-best-practices",
                  "title": "API Testing Best Practices",
                  "description": "Guidelines for implementing automated functional, performance, and security testing throughout the API lifecycle.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 133,
                  "outcomes": [
                    "Shared understanding of the purpose and use of API Testing Best Practices",
                    "A consistent approach to applying API Testing Best Practices",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Test APIs for functionality, security, and performance using automated testing tools.",
                    "Integrate functional and non-functional testing into the CI/CD pipeline to ensure APIs meet quality standards.",
                    "Use automated testing tools to validate API functionality, security, and performance."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                },
                {
                  "id": "apiops-CI-CD-for-apis",
                  "slug": "resources/apiops-CI-CD-for-apis",
                  "title": "APIOps CI/CD For APIs",
                  "description": "Deployment guidance that integrates API lifecycle tasks—design, testing, governance—into continuous integration and delivery pipelines.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 140,
                  "outcomes": [
                    "Shared understanding of the purpose and use of APIOps CI/CD For APIs",
                    "A consistent approach to applying APIOps CI/CD For APIs",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Use CI/CD pipelines to automate build, test, and deployment processes, ensuring consistent quality and traceability.",
                    "Integrate automated tests into the CI/CD pipeline to ensure continuous validation of API quality.",
                    "Implement deployment strategies (e.g., blue-green deployments, canary releases) to minimize risks during API releases.",
                    "Establish a habit of reviewing metrics and planning continuous improvement activities."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                }
              ],
              "evidence": [
                "implementation",
                "pipeline-config",
                "test-report",
                "security-report"
              ]
            },
            {
              "index": 6,
              "id": "api-audit",
              "slug": "method/api-audit",
              "icon": "check-box-outline",
              "title": "Quality & Readiness Assurance",
              "description": "Validate the interface contract, controls, documentation, support model, and operational readiness before release.",
              "whyItMatters": "Reusable capabilities create operational, data, security, privacy, compliance, and consumer-impact risks. Readiness checks reduce surprises before release or production use.",
              "applyInWork": "Use audit and compliance resources to verify that the capability is ready for controlled release and reuse.",
              "outcomes": [
                "Documented readiness for release and reuse",
                "Known gaps and mitigations before release",
                "Evidence for governance, compliance, support, and operational approval",
                "Reduced risk of issues in production"
              ],
              "steps": [
                {
                  "text": "Use the audit checklist as a reusable quality checklist for interface contract, documentation, security, performance, and compliance readiness.",
                  "resourceId": "api-audit-checklist",
                  "resourceTitle": "API Audit Checklist",
                  "canvasId": null
                },
                {
                  "text": "Use checklists, linters, and testing tools to verify consistency and conformance with standards.",
                  "resourceId": "api-compliance-best-practices",
                  "resourceTitle": "API Compliance Best Practices",
                  "canvasId": null
                },
                {
                  "text": "Collaborate with governance teams and domain experts to ensure the capability is ready for production.",
                  "resourceTitle": "",
                  "canvasId": null
                }
              ],
              "questions": [
                "Use the audit checklist as a reusable quality checklist for interface contract, documentation, security, performance, and compliance readiness.",
                "Use checklists, linters, and testing tools to verify consistency and conformance with standards.",
                "Collaborate with governance teams and domain experts to ensure the capability is ready for production.",
                "Use audit and compliance resources to verify that the capability is ready for controlled release and reuse.",
                "Reusable capabilities create operational, data, security, privacy, compliance, and consumer-impact risks. Readiness checks reduce surprises before release or production use."
              ],
              "criteria": [
                "architecture-patterns-validated",
                "design-reflects-business-value",
                "api-description-available",
                "api-consistency",
                "api-contract-tested"
              ],
              "criteriaDetails": [
                {
                  "id": "architecture-patterns-validated",
                  "title": "The chosen architecture, platform, and implementation style have been validated with the relevant architecture, security, and platform stakeholders.",
                  "description": "The chosen API architecture and platform patterns have been validated with the relevant architecture, security, and platform stakeholders."
                },
                {
                  "id": "design-reflects-business-value",
                  "title": "The interface design and exposed capabilities trace back to business value and consumer needs.",
                  "description": "The API design and exposed capabilities clearly trace back to business value and user needs."
                },
                {
                  "id": "api-description-available",
                  "title": "The interface and its capabilities are documented clearly enough for review, audit, and onboarding.",
                  "description": "The API and its exposed capabilities are described clearly enough for review, audit, and onboarding."
                },
                {
                  "id": "api-consistency",
                  "title": "The interface design follows agreed design standards and conventions.",
                  "description": "The API design follows our shared API product and design conventions."
                },
                {
                  "id": "api-contract-tested",
                  "title": "The interface contract has been validated and tested against functional and non-functional requirements.",
                  "description": "The API contract is tested and meets functional and non-functional requirements."
                }
              ],
              "baseTitle": "Quality & Readiness Assurance",
              "group": "Capability Lifecycle Core Stations",
              "lifecycleStage": "publishing",
              "stakeholders": [
                {
                  "id": "governance-specialist",
                  "sourceKey": "governance-specialist",
                  "sourceStakeholderId": "governance-specialist",
                  "title": "API Governance Owner",
                  "description": "Represents review, audit, and organization-wide governance practices for API quality and conformity.",
                  "involvement": "lead",
                  "responsibilities": []
                },
                {
                  "id": "capability-owner",
                  "sourceKey": "capability-owner",
                  "sourceStakeholderId": "capability-owner",
                  "title": "Capability Owner",
                  "description": "Owns the capability vision, value, priorities, lifecycle, and reuse across consumers.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "compliance-specialist",
                  "sourceKey": "compliance-specialist",
                  "sourceStakeholderId": "compliance-specialist",
                  "title": "Compliance and Legal Specialist",
                  "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "security-specialist",
                  "sourceKey": "security-specialist",
                  "sourceStakeholderId": "security-specialist",
                  "title": "Security Specialist",
                  "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "api-designer",
                  "sourceKey": "api-designer",
                  "sourceStakeholderId": "api-designer",
                  "title": "API Designer",
                  "description": "Shapes the interface contract, interaction model, consistency, and usability of the exposed capabilities.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "api-engineer",
                  "sourceKey": "api-engineer",
                  "sourceStakeholderId": "api-engineer",
                  "title": "Delivery Engineer",
                  "description": "Owns implementation, automation, testing, and release flow concerns needed to deliver the capability, API, or automation reliably.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "platform-architect",
                  "sourceKey": "platform-architect",
                  "sourceStakeholderId": "platform-architect",
                  "title": "Platform Architect",
                  "description": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "operations-specialist",
                  "sourceKey": "operations-specialist",
                  "sourceStakeholderId": "operations-specialist",
                  "title": "Support and Operations Owner",
                  "description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
                  "involvement": "consulted",
                  "responsibilities": []
                }
              ],
              "resources": [
                {
                  "id": "api-audit-checklist",
                  "slug": "resources/api-audit-checklist",
                  "title": "API Audit Checklist",
                  "description": "A lifecycle-based checklist to verify API readiness across design, delivery, publishing, and compliance using defined audit criteria and evidence.",
                  "category": "checklist",
                  "icon": "check-box-outline",
                  "order": 13,
                  "outcomes": [
                    "Shared understanding of the purpose and use of API Audit Checklist",
                    "A consistent approach to applying API Audit Checklist",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Use the API Audit Checklist to ensure the API design meets functional and non-functional requirements, including security, performance, and compliance.",
                    "Conduct audits to assess lifecycle coverage and verify that the API meets business, design, and operational standards.",
                    "Ensure that documentation, security models, gateway configuration, and legal requirements are clearly defined, validated, and supported by evidence."
                  ],
                  "canvasId": null,
                  "sourcePath": "src/snippets/api-audit-checklist.json",
                  "sourceUrl": null,
                  "contentMarkdown": "{\r\n  \"profiles\": {\r\n    \"read-only\": {\r\n      \"description\": \"API profile that is read-only and does not allow create, update, or delete operations.\"\r\n    },\r\n    \"full-crud\": {\r\n      \"description\": \"General API profile that allows create, update, and delete operations.\"\r\n    }\r\n  },\r\n  \"lifecycleStages\": [\r\n    {\r\n      \"id\": \"strategy\",\r\n      \"title\": \"Strategy\",\r\n      \"readinessLabel\": \"Strategy is Ready When...\",\r\n      \"order\": 1\r\n    },\r\n    {\r\n      \"id\": \"architecture\",\r\n      \"title\": \"Architecture\",\r\n      \"readinessLabel\": \"Architecture is Ready When...\",\r\n      \"order\": 2\r\n    },\r\n    {\r\n      \"id\": \"design\",\r\n      \"title\": \"Design\",\r\n      \"readinessLabel\": \"Design is Ready When...\",\r\n      \"order\": 3\r\n    },\r\n    {\r\n      \"id\": \"delivery\",\r\n      \"title\": \"Delivery\",\r\n      \"readinessLabel\": \"Delivery is Ready When...\",\r\n      \"order\": 4\r\n    },\r\n    {\r\n      \"id\": \"publishing\",\r\n      \"title\": \"Publishing\",\r\n      \"readinessLabel\": \"Publishing is Ready When...\",\r\n      \"order\": 5\r\n    },\r\n    {\r\n      \"id\": \"improving\",\r\n      \"title\": \"Improving\",\r\n      \"readinessLabel\": \"Improving is Ready When...\",\r\n      \"order\": 6\r\n    }\r\n  ],\r\n  \"stages\": [\r\n    {\r\n      \"id\": \"strategy\",\r\n      \"title\": \"Strategy\",\r\n      \"readinessLabel\": \"Strategy is Ready When...\",\r\n      \"order\": 1,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"based-on-clear-business-needs\",\r\n          \"label\": \"API is based on clear business needs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"strategy\",\r\n          \"producedByStation\": [\r\n            \"api-product-strategy\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"business-goals-defined\",\r\n            \"market-research-done\",\r\n            \"stakeholder-approval\",\r\n            \"metrics-feedback-available\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DOMAIN-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiBusinessModelCanvas\",\r\n            \"apiValuePropositionCanvas\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"design-artifact\",\r\n            \"documentation\",\r\n            \"research\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-product-strategy/apiValuePropositionCanvas.empty.json\",\r\n            \"specs/canvases/api-product-strategy/apiBusinessModelCanvas.empty.json\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"concept-items-audited\",\r\n          \"label\": \"All concept checklist items are audited\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"aggregate\",\r\n          \"check\": {\r\n            \"type\": \"stageCoverage\",\r\n            \"stageId\": \"strategy\"\r\n          },\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"strategy\",\r\n          \"producedByStation\": [\r\n            \"api-product-strategy\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"business-goals-defined\",\r\n            \"market-research-done\",\r\n            \"stakeholder-approval\",\r\n            \"metrics-feedback-available\",\r\n            \"api-opportunity-documented\",\r\n            \"api-reusability\",\r\n            \"value-prop-validated\",\r\n            \"consumer-segments-identified\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"report\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"audit/concept-review-report.json\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"architecture\",\r\n      \"title\": \"Architecture\",\r\n      \"readinessLabel\": \"Architecture is Ready When...\",\r\n      \"order\": 2,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"versioning-decided\",\r\n          \"label\": \"Versioning strategy decided and supported by gateway\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"architecture\",\r\n          \"producedByStation\": [\r\n            \"api-platform-architecture\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-roadmap-defined\",\r\n            \"api-reusability\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-VERSION-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"contract-first-design\",\r\n            \"api-versioning-best-practices\",\r\n            \"apiops-CI-CD-for-apis\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"ci-cd\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"docs/api/architecture/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"only-via-gateway\",\r\n          \"label\": \"Only accessible via API gateway\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"architecture\",\r\n          \"producedByStation\": [\r\n            \"api-platform-architecture\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-reusability\",\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-02\",\r\n            \"REST-CAPACITY-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"businessImpactCanvas\",\r\n            \"locationsCanvas\",\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"gateway-config\",\r\n            \"infra-config\",\r\n            \"security-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/architecture/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"rate-limits-enforced\",\r\n          \"label\": \"Rate limits are enforced\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"architecture\",\r\n          \"producedByStation\": [\r\n            \"api-platform-architecture\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-roadmap-defined\",\r\n            \"api-reusability\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CAPACITY-01\",\r\n            \"REST-OBS-01\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"capacityCanvas\",\r\n            \"api-security-best-practices\",\r\n            \"scalable-infrastructure-best-practices\",\r\n            \"api-metrics-and-analytics\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"gateway-config\",\r\n            \"runtime\",\r\n            \"monitoring\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-platform-architecture/capacityCanvas.empty.json\",\r\n            \"docs/api/architecture/README.md\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"design\",\r\n      \"title\": \"Design\",\r\n      \"readinessLabel\": \"Design is Ready When...\",\r\n      \"order\": 3,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"endpoint-descriptions-present\",\r\n          \"label\": \"Endpoints have business value and feature descriptions\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"operationDescriptions\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"value-prop-validated\",\r\n            \"api-opportunity-documented\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CX-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiValuePropositionCanvas\",\r\n            \"customerJourneyCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"design-artifact\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"specs/canvases/api-product-strategy/apiValuePropositionCanvas.empty.json\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"hides-raw-backend-data\",\r\n          \"label\": \"API hides raw backend data and is designed for shared use\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"hide-backend-discrepancies\",\r\n            \"design-reflects-business-value\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DOMAIN-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"interactionCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"design-artifact\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-product-strategy/domainCanvas.empty.json\",\r\n            \"specs/canvases/api-design/interactionCanvas.empty.json\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"design-consistent\",\r\n          \"label\": \"API design is consistent with other APIs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-platform-architecture\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"architecture-patterns-validated\",\r\n            \"api-reusability\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DOMAIN-02\",\r\n            \"REST-CX-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"documentation\",\r\n            \"design-artifact\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-design/restCanvas.empty.json\",\r\n            \"docs/api/design/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"descriptive-english-naming\",\r\n          \"label\": \"Data and attribute naming uses descriptive English\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"fieldNamesDescriptive\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-NAMING-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"mandatory-fields-specified\",\r\n          \"label\": \"Mandatory fields are specified\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"requiredFieldsPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-VALIDATION-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"contract\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"dates-use-iso\",\r\n          \"label\": \"Dates use ISO format with timezone\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"dateFormatTimezone\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DATA-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"general-data-uses-standard-values\",\r\n          \"label\": \"General data uses standard values\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"standardizedEnumsOrPatterns\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"design-reflects-business-value\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DATA-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"field-names-avoid-acronyms\",\r\n          \"label\": \"Field names avoid acronyms and use full words\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"avoidAcronyms\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-NAMING-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"create-returns-identifiers\",\r\n          \"label\": \"Creating new resources returns identifiers\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is read-only and does not create resources.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-201-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"paths-max-two-resources\",\r\n          \"label\": \"Endpoint paths contain max two resources or sub-resources\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"pathDepthMax\",\r\n            \"maxDepth\": 2\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PATH-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"examples-present\",\r\n          \"label\": \"Endpoints and attributes include examples\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"examplesPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CX-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"restCanvas\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"post-for-create-update\",\r\n          \"label\": \"POST is used for create or update\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose create or update operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"design-reflects-business-value\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-POST-01\",\r\n            \"REST-HTTP-PUT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"delete-for-remove\",\r\n          \"label\": \"DELETE is used to remove resources\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose delete operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-DELETE-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"get-no-request-body\",\r\n          \"label\": \"GET has no request body and returns content\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"getNoRequestBody\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-GET-01\",\r\n            \"REST-RESP-200-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"get-empty-returns-204\",\r\n          \"label\": \"GET returns 204 if response body is empty\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"The current contract returns content for all GET operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-204-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"post-returns-200\",\r\n          \"label\": \"POST returns 200 OK when updating\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose POST updates.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-200-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"post-returns-201\",\r\n          \"label\": \"POST returns 201 Created with ID on create\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose POST creates.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-201-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"delete-returns-204\",\r\n          \"label\": \"DELETE returns 204 on success\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose DELETE operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-204-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"400-errors-specific\",\r\n          \"label\": \"400 errors provide specific error information\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"errorResponsesSpecific\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-ERROR-400-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"restCanvas\",\r\n            \"api-audit-checklist\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"401-unauthorized\",\r\n          \"label\": \"401 Unauthorized for wrong credentials\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"The current public storefront contract is intentionally unauthenticated.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-ERROR-401-01\",\r\n            \"REST-SEC-01\",\r\n            \"REST-SEC-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"security-config\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"403-forbidden\",\r\n          \"label\": \"403 Forbidden for unauthorized operations\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"The current profile is public read-only and exposes no unauthorized operations.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-ERROR-403-01\",\r\n            \"REST-SEC-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"security-config\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"spec-contains-schemas\",\r\n          \"label\": \"Spec contains request and response schema\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"schemasPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CONTRACT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"contract-first-design\",\r\n            \"restCanvas\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"contract\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"pseudo-identifiers\",\r\n          \"label\": \"UUIDs or pseudo-identifiers instead of DB IDs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"opaqueIdentifiers\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"hide-backend-discrepancies\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-07\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"contract-first-design\",\r\n            \"api-security-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"no-sensitive-data-in-urls\",\r\n          \"label\": \"No sensitive data in URLs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"noSensitiveDataInPaths\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"hide-backend-discrepancies\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-06\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"contract-first-design\",\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"http-methods-match-resources\",\r\n          \"label\": \"HTTP methods only for intended resources\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"methodResourceConsistency\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-GET-01\",\r\n            \"REST-HTTP-POST-01\",\r\n            \"REST-HTTP-PUT-01\",\r\n            \"REST-HTTP-DELETE-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"delivery\",\r\n      \"title\": \"Delivery\",\r\n      \"readinessLabel\": \"Delivery is Ready When...\",\r\n      \"order\": 4,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"design-items-audited\",\r\n          \"label\": \"All prototype and design items are audited\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"aggregate\",\r\n          \"check\": {\r\n            \"type\": \"stageCoverage\",\r\n            \"stageId\": \"design\"\r\n          },\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"design-reflects-business-value\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"report\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"audit/production-readiness-review.json\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"spec-validated-on-change\",\r\n          \"label\": \"Spec validated on every change\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"validationWorkflowPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-audit-checklist\",\r\n            \"contract-first-design\",\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"api-testing-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"ci-cd\",\r\n            \"spec\",\r\n            \"test\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \".github/workflows/openapi-lint.yml\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"schema-and-examples-pass\",\r\n          \"label\": \"Schema and examples pass validation\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"examplesPassValidation\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"architecture-patterns-validated\",\r\n            \"api-contract-tested\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-01\",\r\n            \"REST-CONTRACT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"contract-first-design\",\r\n            \"api-audit-checklist\",\r\n            \"api-testing-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"test\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"uses-https\",\r\n          \"label\": \"Uses HTTPS or encrypted protocols\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-05\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"auth-protection\",\r\n          \"label\": \"Endpoints protected by authentication\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is intentionally public read-only.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-01\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"gateway-config\",\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"token-auth\",\r\n          \"label\": \"Token-based authentication\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is intentionally public read-only.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"csrf-protection\",\r\n          \"label\": \"Protected against CSRF\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is intentionally public read-only.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-08\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-development-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"code\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"inputs-auto-validated\",\r\n          \"label\": \"Inputs auto-validated by framework\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-VALIDATION-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-development-best-practices\",\r\n            \"contract-first-design\",\r\n            \"api-testing-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"code\",\r\n            \"test\",\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"docs/api/delivery/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"outputs-auto-escaped\",\r\n          \"label\": \"Outputs auto-escaped by framework\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"JSON APIs do not typically require output escaping in the same way as HTML rendering.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-development-best-practices\",\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"code\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"encryption-in-transit\",\r\n          \"label\": \"Encryption for data in transit and storage\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-05\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\",\r\n            \"api-metrics-and-analytics\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"infra-config\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"message-integrity\",\r\n          \"label\": \"Message integrity implemented\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-OBS-01\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"api-compliance-best-practices\",\r\n            \"api-metrics-and-analytics\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"monitoring\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/architecture/README.md\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"publishing\",\r\n      \"title\": \"Publishing\",\r\n      \"readinessLabel\": \"Publishing is Ready When...\",\r\n      \"order\": 5,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"published-via-api-management\",\r\n          \"label\": \"Published via API management\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"api-onboarding-best-practices\",\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"gateway-config\",\r\n            \"ci-cd\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \".github/workflows/openapi-lint.yml\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"visible-in-dev-portal\",\r\n          \"label\": \"Visible in developer portal\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-documentation-ready\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"api-community-engagement-strategies\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"documentation\",\r\n            \"runtime\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"docs-auto-generated\",\r\n          \"label\": \"Docs auto-generated from spec and schema\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\",\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-documentation-ready\",\r\n            \"api-ready-for-publishing\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CONTRACT-02\",\r\n            \"REST-PUBLISH-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"contract-first-design\",\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"api-onboarding-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"documentation\",\r\n            \"ci-cd\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"docs/api/audit/design-audit.read-only.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"spec-auto-updated\",\r\n          \"label\": \"Spec auto-updated to gateway and dev portal\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\",\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CONTRACT-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"contract-first-design\",\r\n            \"api-onboarding-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"ci-cd\",\r\n            \"gateway-config\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \".github/workflows/openapi-lint.yml\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"official-domain\",\r\n          \"label\": \"Published under official organization domain\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"documentation\",\r\n            \"runtime\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"improving\",\r\n      \"title\": \"Improving\",\r\n      \"readinessLabel\": \"Improving is Ready When...\",\r\n      \"order\": 6,\r\n      \"items\": []\r\n    }\r\n  ],\r\n  \"guidelines\": [\r\n    {\r\n      \"id\": \"REST-CONTRACT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST implement endpoints, parameters, request bodies, response bodies, and error responses as defined in the validated OpenAPI contract.\",\r\n      \"relatedAuditItems\": [\r\n        \"spec-contains-schemas\",\r\n        \"schema-and-examples-pass\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CONTRACT-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST keep the implementation, published OpenAPI description, gateway configuration, and developer portal documentation aligned on every change.\",\r\n      \"relatedAuditItems\": [\r\n        \"docs-auto-generated\",\r\n        \"spec-auto-updated\",\r\n        \"spec-validated-on-change\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-VALIDATION-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST validate path parameters, query parameters, headers, and JSON request bodies against the OpenAPI schema before business processing.\",\r\n      \"relatedAuditItems\": [\r\n        \"mandatory-fields-specified\",\r\n        \"400-errors-specific\",\r\n        \"inputs-auto-validated\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DOMAIN-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST expose business-oriented resources and attributes rather than raw backend tables, internal service payloads, or system-specific field names.\",\r\n      \"relatedAuditItems\": [\r\n        \"based-on-clear-business-needs\",\r\n        \"hides-raw-backend-data\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DOMAIN-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST preserve validated meanings of entities, attributes, statuses, and source-of-truth rules across all endpoints and operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"design-consistent\",\r\n        \"general-data-uses-standard-values\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-NAMING-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST use descriptive English names for resources and attributes.\",\r\n      \"relatedAuditItems\": [\r\n        \"descriptive-english-naming\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-NAMING-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST avoid unexplained acronyms in public field and resource names.\",\r\n      \"relatedAuditItems\": [\r\n        \"field-names-avoid-acronyms\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DATA-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST use ISO date-time values with timezone information where dates are exposed.\",\r\n      \"relatedAuditItems\": [\r\n        \"dates-use-iso\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DATA-02\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API SHOULD use standard codes, controlled vocabularies, and standardized value sets where applicable.\",\r\n      \"relatedAuditItems\": [\r\n        \"general-data-uses-standard-values\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API MUST describe the business value and feature intent of each endpoint or capability.\",\r\n      \"relatedAuditItems\": [\r\n        \"endpoint-descriptions-present\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API MUST include examples for endpoints, request bodies, response bodies, and key attributes.\",\r\n      \"relatedAuditItems\": [\r\n        \"examples-present\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-03\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API SHOULD use consistent pagination, filtering, sorting, and response conventions across resources.\",\r\n      \"relatedAuditItems\": [\r\n        \"design-consistent\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-GET-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use GET for safe read-only operations and MUST NOT define a request body for GET operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-no-request-body\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-POST-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use POST for resource creation and other non-idempotent operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"post-for-create-update\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-PUT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use PUT only for full resource replacement.\",\r\n      \"relatedAuditItems\": [\r\n        \"post-for-create-update\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-DELETE-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use DELETE to remove resources.\",\r\n      \"relatedAuditItems\": [\r\n        \"delete-for-remove\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PATH-01\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"resource-modeling\",\r\n      \"requirement\": \"The REST API SHOULD keep endpoint paths shallow and avoid more than two resource or sub-resource levels unless explicitly justified.\",\r\n      \"relatedAuditItems\": [\r\n        \"paths-max-two-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-200-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 200 OK for successful reads and updates that include a response body.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-no-request-body\",\r\n        \"post-returns-200\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-201-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 201 Created and the created resource identifier when a new resource is created.\",\r\n      \"relatedAuditItems\": [\r\n        \"create-returns-identifiers\",\r\n        \"post-returns-201\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-204-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 204 No Content for successful delete operations that do not return a body.\",\r\n      \"relatedAuditItems\": [\r\n        \"delete-returns-204\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-204-02\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API SHOULD return 204 No Content for successful operations that intentionally return no response body.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-empty-returns-204\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-400-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST define 400 Bad Request responses with specific and actionable validation error information.\",\r\n      \"relatedAuditItems\": [\r\n        \"400-errors-specific\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-401-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST return 401 Unauthorized for missing or invalid credentials.\",\r\n      \"relatedAuditItems\": [\r\n        \"401-unauthorized\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-403-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST return 403 Forbidden for authenticated clients lacking sufficient permission.\",\r\n      \"relatedAuditItems\": [\r\n        \"403-forbidden\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-VERSION-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"versioning\",\r\n      \"requirement\": \"The REST API MUST define a versioning strategy before production release, and the strategy MUST be supportable by the API gateway.\",\r\n      \"relatedAuditItems\": [\r\n        \"versioning-decided\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST require authentication for protected endpoints.\",\r\n      \"relatedAuditItems\": [\r\n        \"auth-protection\",\r\n        \"401-unauthorized\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST use token-based authentication or another approved modern authentication mechanism for protected endpoints.\",\r\n      \"relatedAuditItems\": [\r\n        \"token-auth\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-03\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST enforce object-level and function-level authorization on every protected operation.\",\r\n      \"relatedAuditItems\": [\r\n        \"401-unauthorized\",\r\n        \"403-forbidden\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-04\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST mitigate OWASP API risks including broken object level authorization, broken function level authorization, injection, and unrestricted resource consumption.\",\r\n      \"relatedAuditItems\": [\r\n        \"auth-protection\",\r\n        \"rate-limits-enforced\",\r\n        \"no-sensitive-data-in-urls\",\r\n        \"message-integrity\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-05\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST use HTTPS or another approved encrypted protocol for all traffic.\",\r\n      \"relatedAuditItems\": [\r\n        \"uses-https\",\r\n        \"encryption-in-transit\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-06\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST NOT expose sensitive information in URLs, query strings, logs, or unnecessary response fields.\",\r\n      \"relatedAuditItems\": [\r\n        \"no-sensitive-data-in-urls\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-07\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API SHOULD use UUIDs or other non-sequential public identifiers where direct database identifiers would increase exposure risk.\",\r\n      \"relatedAuditItems\": [\r\n        \"pseudo-identifiers\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-08\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST implement CSRF protection where relevant to the authentication model and client interaction pattern.\",\r\n      \"relatedAuditItems\": [\r\n        \"csrf-protection\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CAPACITY-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"resilience-capacity\",\r\n      \"requirement\": \"The REST API MUST define and enforce rate limits, throttling, or quotas according to capacity expectations.\",\r\n      \"relatedAuditItems\": [\r\n        \"rate-limits-enforced\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CAPACITY-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"resilience-capacity\",\r\n      \"requirement\": \"The REST API MUST implement resilience controls such as timeouts, fallback behavior, and degradation handling according to business impact.\",\r\n      \"relatedAuditItems\": [\r\n        \"only-via-gateway\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-OBS-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"observability\",\r\n      \"requirement\": \"The REST API MUST implement logs, metrics, and monitoring needed to observe validation failures, auth failures, traffic, latency, and dependency health.\",\r\n      \"relatedAuditItems\": [\r\n        \"rate-limits-enforced\",\r\n        \"message-integrity\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be published through an API management platform.\",\r\n      \"relatedAuditItems\": [\r\n        \"published-via-api-management\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be accessible only through approved API gateway paths and managed entry points.\",\r\n      \"relatedAuditItems\": [\r\n        \"only-via-gateway\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-03\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API SHOULD be visible in a developer portal with documentation generated from the contract.\",\r\n      \"relatedAuditItems\": [\r\n        \"visible-in-dev-portal\",\r\n        \"docs-auto-generated\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-04\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be published under an approved organizational domain.\",\r\n      \"relatedAuditItems\": [\r\n        \"official-domain\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-AUDIT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST validate the specification, schema, and examples on every change.\",\r\n      \"relatedAuditItems\": [\r\n        \"spec-validated-on-change\",\r\n        \"schema-and-examples-pass\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-AUDIT-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST pass concept, design, security, and production-readiness checks before release.\",\r\n      \"relatedAuditItems\": [\r\n        \"concept-items-audited\",\r\n        \"design-items-audited\"\r\n      ]\r\n    }\r\n  ]\r\n}\r\n",
                  "draft": false
                },
                {
                  "id": "api-compliance-best-practices",
                  "slug": "resources/api-compliance-best-practices",
                  "title": "API Compliance Best Practices",
                  "description": "Ensure APIs meet legal, regulatory, and internal compliance through documentation, controls, and automated validations.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 104,
                  "outcomes": [
                    "Shared understanding of the purpose and use of API Compliance Best Practices",
                    "A consistent approach to applying API Compliance Best Practices",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Document compliance measures and ensure they are communicated to stakeholders and consumers.",
                    "Implement measures to ensure APIs comply with these requirements, including data encryption, access controls, and audit trails.",
                    "Use checklists, linters, and testing tools to verify consistency and conformance with standards."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                }
              ],
              "evidence": [
                "audit-report",
                "compliance-report",
                "security-report",
                "test-report"
              ]
            },
            {
              "index": 7,
              "id": "api-publishing",
              "slug": "method/api-publishing",
              "icon": "deployed-code-outline",
              "title": "Publishing & Enablement",
              "description": "Publish the capability so consumers can discover it, evaluate it, request access, complete onboarding, use it, and get support.",
              "whyItMatters": "Reusable capabilities only create value when consumers can find them, understand their interface contract and service expectations, request access, and know who owns support and lifecycle decisions.",
              "applyInWork": "Publish ownership, documentation, onboarding, support contacts, service expectations, lifecycle status, and access request paths.",
              "outcomes": [
                "A discoverable reusable capability",
                "Clear onboarding, access, support, and service expectations",
                "Lifecycle and ownership information available to consumers and governance teams",
                "Consumers enabled to use and reuse the capability"
              ],
              "steps": [
                {
                  "text": "Publish capability information to the appropriate catalogs, portals, gateways, or environments to support reuse by multiple consumers.",
                  "resourceId": "apiops-CI-CD-for-apis",
                  "resourceTitle": "APIOps CI/CD For APIs",
                  "canvasId": null
                },
                {
                  "text": "Document how consumers find and use the capability, including onboarding processes and registration.",
                  "resourceId": "api-onboarding-best-practices",
                  "resourceTitle": "API Onboarding Best Practices",
                  "canvasId": null
                },
                {
                  "text": "Ensure security models, access configuration, and legal terms are clear and accessible to consumers.",
                  "resourceId": "api-audit-checklist",
                  "resourceTitle": "API Audit Checklist",
                  "canvasId": null
                }
              ],
              "questions": [
                "Publish capability information to the appropriate catalogs, portals, gateways, or environments to support reuse by multiple consumers.",
                "Document how consumers find and use the capability, including onboarding processes and registration.",
                "Ensure security models, access configuration, and legal terms are clear and accessible to consumers.",
                "Publish ownership, documentation, onboarding, support contacts, service expectations, lifecycle status, and access request paths.",
                "Reusable capabilities only create value when consumers can find them, understand their interface contract and service expectations, request access, and know who owns support and lifecycle decisions."
              ],
              "criteria": [
                "audit-passed",
                "audit-reports-shared",
                "api-ready-for-publishing",
                "api-documentation-ready"
              ],
              "criteriaDetails": [
                {
                  "id": "audit-passed",
                  "title": "The solution passes quality, security, compliance, and readiness checks.",
                  "description": "The API passes compliance, security, and audit checks."
                },
                {
                  "id": "audit-reports-shared",
                  "title": "Audit findings and remediation decisions are shared with the relevant stakeholders.",
                  "description": "Audit findings and remediation decisions are shared with the relevant stakeholders."
                },
                {
                  "id": "api-ready-for-publishing",
                  "title": "The capability is ready to be published or released through the selected delivery mechanism.",
                  "description": "The API is ready to be deployed and exposed through the intended gateways and environments."
                },
                {
                  "id": "api-documentation-ready",
                  "title": "Consumer-facing documentation and onboarding materials are ready.",
                  "description": "Consumer-facing API documentation is complete enough for publishing and onboarding."
                }
              ],
              "baseTitle": "Publishing & Enablement",
              "group": "Capability Lifecycle Core Stations",
              "lifecycleStage": "publishing",
              "stakeholders": [
                {
                  "id": "capability-owner",
                  "sourceKey": "capability-owner",
                  "sourceStakeholderId": "capability-owner",
                  "title": "Capability Owner",
                  "description": "Owns the capability vision, value, priorities, lifecycle, and reuse across consumers.",
                  "involvement": "lead",
                  "responsibilities": []
                },
                {
                  "id": "api-consumer-specialist",
                  "sourceKey": "api-consumer-specialist",
                  "sourceStakeholderId": "api-consumer-specialist",
                  "title": "API Consumer Representative",
                  "description": "Represents the needs of developers, integrators, or other API consumers who use the API directly.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "api-devrel-specialist",
                  "sourceKey": "api-devrel-specialist",
                  "sourceStakeholderId": "api-devrel-specialist",
                  "title": "Documentation and DevRel Owner",
                  "description": "Owns onboarding content, developer communication, and documentation quality for API consumers.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "operations-specialist",
                  "sourceKey": "operations-specialist",
                  "sourceStakeholderId": "operations-specialist",
                  "title": "Support and Operations Owner",
                  "description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "business-owner",
                  "sourceKey": "business-owner",
                  "sourceStakeholderId": "business-owner",
                  "title": "Business Owner",
                  "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "partner-specialist",
                  "sourceKey": "partner-specialist",
                  "sourceStakeholderId": "partner-specialist",
                  "title": "Partner or Vendor Manager",
                  "description": "Coordinates external partner, supplier, or vendor relationships that influence capability or API strategy and delivery.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "security-specialist",
                  "sourceKey": "security-specialist",
                  "sourceStakeholderId": "security-specialist",
                  "title": "Security Specialist",
                  "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
                  "involvement": "consulted",
                  "responsibilities": []
                }
              ],
              "resources": [
                {
                  "id": "api-onboarding-best-practices",
                  "slug": "resources/api-onboarding-best-practices",
                  "title": "API Onboarding Best Practices",
                  "description": "Best practices to streamline API consumer onboarding journeys with step-by-step registration, discovery, and first-call guidance.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 121,
                  "outcomes": [
                    "Shared understanding of the purpose and use of API Onboarding Best Practices",
                    "A consistent approach to applying API Onboarding Best Practices",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Define the API consumer journey from discovery to troubleshooting, identifying key touchpoints and pain points.",
                    "Develop onboarding processes and resources to help API consumers understand how to use APIs effectively.",
                    "Document how consumers find and use the API, including onboarding processes and registration."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                },
                {
                  "id": "service-agreement-template",
                  "slug": "resources/service-agreement-template",
                  "title": "Service Agreement Template",
                  "description": "A customizable agreement format that defines expectations, SLAs, responsibilities, and access terms for API consumption.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 172,
                  "outcomes": [
                    "Shared understanding of the purpose and use of Service Agreement Template",
                    "A consistent approach to applying Service Agreement Template",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Define service agreements that outline the expectations, service levels, and responsibilities for each API.",
                    "Use standardized formats to create machine-readable service agreements that are easy to share and validate.",
                    "Ensure service agreements are reviewed and approved by stakeholders to ensure alignment and clarity."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                }
              ],
              "evidence": [
                "gateway-config",
                "developer-portal",
                "documentation",
                "release-record"
              ]
            },
            {
              "index": 8,
              "id": "monitoring-and-improving",
              "slug": "method/monitoring-and-improving",
              "icon": "analytics-outline",
              "title": "Monitoring & Improvement",
              "description": "Monitor capability health, consumer outcomes, reliability, reuse, and improvement opportunities.",
              "whyItMatters": "Capabilities need continuous feedback to stay reliable, valuable, cost-effective, and reusable as consumers, systems, data, and platforms change.",
              "applyInWork": "Use metrics, analytics, and engagement practices to improve the capability over time.",
              "outcomes": [
                "Measured capability health and value",
                "Improvement backlog informed by operational and consumer feedback",
                "Reuse, reliability, data quality, and cost signals available to owners",
                "Continuous improvement aligned with consumer needs"
              ],
              "steps": [
                {
                  "text": "Use metrics and analytics guidance to define capability usage, reliability, data quality, cost, adoption, and consumer-value measures.",
                  "resourceId": "api-metrics-and-analytics",
                  "resourceTitle": "API Metrics And Analytics",
                  "canvasId": null
                },
                {
                  "text": "Analyze usage metrics and incorporate consumer feedback into capability iterations.",
                  "resourceId": "api-community-engagement-strategies",
                  "resourceTitle": "API Community Engagement Strategies",
                  "canvasId": null
                },
                {
                  "text": "Establish a habit of reviewing metrics and planning continuous improvement activities.",
                  "resourceId": "apiops-CI-CD-for-apis",
                  "resourceTitle": "APIOps CI/CD For APIs",
                  "canvasId": null
                }
              ],
              "questions": [
                "Use metrics and analytics guidance to define capability usage, reliability, data quality, cost, adoption, and consumer-value measures.",
                "Analyze usage metrics and incorporate consumer feedback into capability iterations.",
                "Establish a habit of reviewing metrics and planning continuous improvement activities.",
                "Use metrics, analytics, and engagement practices to improve the capability over time.",
                "Capabilities need continuous feedback to stay reliable, valuable, cost-effective, and reusable as consumers, systems, data, and platforms change."
              ],
              "criteria": [
                "api-documentation-ready",
                "consumer-support-ready",
                "legal-compliance-clear"
              ],
              "criteriaDetails": [
                {
                  "id": "api-documentation-ready",
                  "title": "Consumer-facing documentation and onboarding materials are ready.",
                  "description": "Consumer-facing API documentation is complete enough for publishing and onboarding."
                },
                {
                  "id": "consumer-support-ready",
                  "title": "Consumer onboarding, support, and communication processes are ready.",
                  "description": "Registration, support, and communication processes are ready for API consumers."
                },
                {
                  "id": "legal-compliance-clear",
                  "title": "Legal, privacy, and compliance requirements for publishing or release are defined and understood.",
                  "description": "Legal, privacy, and compliance requirements for publishing are defined and understood."
                }
              ],
              "baseTitle": "Monitoring & Improvement",
              "group": "Capability Lifecycle Core Stations",
              "lifecycleStage": "improving",
              "stakeholders": [
                {
                  "id": "capability-owner",
                  "sourceKey": "capability-owner",
                  "sourceStakeholderId": "capability-owner",
                  "title": "Capability Owner",
                  "description": "Owns the capability vision, value, priorities, lifecycle, and reuse across consumers.",
                  "involvement": "lead",
                  "responsibilities": []
                },
                {
                  "id": "api-consumer-specialist",
                  "sourceKey": "api-consumer-specialist",
                  "sourceStakeholderId": "api-consumer-specialist",
                  "title": "API Consumer Representative",
                  "description": "Represents the needs of developers, integrators, or other API consumers who use the API directly.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "business-owner",
                  "sourceKey": "business-owner",
                  "sourceStakeholderId": "business-owner",
                  "title": "Business Owner",
                  "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "operations-specialist",
                  "sourceKey": "operations-specialist",
                  "sourceStakeholderId": "operations-specialist",
                  "title": "Support and Operations Owner",
                  "description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "compliance-specialist",
                  "sourceKey": "compliance-specialist",
                  "sourceStakeholderId": "compliance-specialist",
                  "title": "Compliance and Legal Specialist",
                  "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "api-devrel-specialist",
                  "sourceKey": "api-devrel-specialist",
                  "sourceStakeholderId": "api-devrel-specialist",
                  "title": "Documentation and DevRel Owner",
                  "description": "Owns onboarding content, developer communication, and documentation quality for API consumers.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "platform-architect",
                  "sourceKey": "platform-architect",
                  "sourceStakeholderId": "platform-architect",
                  "title": "Platform Architect",
                  "description": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "security-specialist",
                  "sourceKey": "security-specialist",
                  "sourceStakeholderId": "security-specialist",
                  "title": "Security Specialist",
                  "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
                  "involvement": "consulted",
                  "responsibilities": []
                }
              ],
              "resources": [
                {
                  "id": "api-metrics-and-analytics",
                  "slug": "resources/api-metrics-and-analytics",
                  "title": "API Metrics And Analytics",
                  "description": "A resource for defining, collecting, and analyzing API performance and usage data to align technical KPIs with business outcomes.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 119,
                  "outcomes": [
                    "Shared understanding of the purpose and use of API Metrics And Analytics",
                    "A consistent approach to applying API Metrics And Analytics",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Identify key performance indicators (KPIs) to measure API success against business goals.",
                    "Define and monitor performance metrics (e.g., API calls, latency, error rates) and adoption metrics (e.g., NPS).",
                    "Monitor API initiatives to ensure adherence to operating guidelines and governance practices"
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                },
                {
                  "id": "api-community-engagement-strategies",
                  "slug": "resources/api-community-engagement-strategies",
                  "title": "API Community Engagement Strategies",
                  "description": "A playbook for fostering API adoption by cultivating communities through content, support channels, feedback loops, and social engagement strategies.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 103,
                  "outcomes": [
                    "Shared understanding of the purpose and use of API Community Engagement Strategies",
                    "A consistent approach to applying API Community Engagement Strategies",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Develop marketing strategies to promote APIs to target audiences, including social media, blogs, and webinars.",
                    "Create promotional materials (e.g., case studies, success stories) that highlight the value and benefits of APIs.",
                    "Create educational materials (e.g., tutorials, documentation) that explain API features, benefits, and usage patterns.",
                    "Engage with API consumers through feedback loops, support channels, and community forums to understand their needs and improve API adoption.",
                    "Analyze API usage metrics and incorporate user feedback into API iterations."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                }
              ],
              "evidence": [
                "metrics",
                "consumer-feedback",
                "incident-report",
                "roadmap"
              ]
            }
          ]
        },
        {
          "id": "api-productization-cycle",
          "slug": "api-productization-cycle",
          "title": "API Productization Cycle",
          "description": "The API-focused APIOps Cycles journey for productizing, designing, delivering, publishing, and improving APIs.",
          "purpose": "API-focused method journey for teams that already know the intended implementation style is an API product.",
          "audiences": [],
          "audienceStakeholders": [
            {
              "id": "api-product-owner",
              "sourceKey": "api-product-owner",
              "sourceStakeholderId": "api-product-owner",
              "title": "API Product Owner",
              "description": "Drives the API opportunity, prioritization, and product-level decisions across the lifecycle.",
              "involvement": "lead",
              "responsibilities": [
                {
                  "resourceId": "apiValuePropositionCanvas",
                  "resourceTitle": "API Value Proposition Canvas",
                  "canvasId": "apiValuePropositionCanvas",
                  "role": "suggested-answer-owner"
                },
                {
                  "resourceId": "apiBusinessModelCanvas",
                  "resourceTitle": "API Business Model Canvas",
                  "canvasId": "apiBusinessModelCanvas",
                  "role": "suggested-answer-owner"
                }
              ]
            },
            {
              "id": "business-owner",
              "sourceKey": "business-owner",
              "sourceStakeholderId": "business-owner",
              "title": "Business Owner",
              "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
              "involvement": "core",
              "responsibilities": [
                {
                  "resourceId": "customerJourneyCanvas",
                  "resourceTitle": "Customer Journey Canvas",
                  "canvasId": "customerJourneyCanvas",
                  "role": "suggested-answer-owner"
                }
              ]
            },
            {
              "id": "customer-specialist",
              "sourceKey": "customer-specialist",
              "sourceStakeholderId": "customer-specialist",
              "title": "Customer or Partner Representative",
              "description": "Contributes the business customer or partner perspective for the journey, value, and collaboration model.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "domain-specialist",
              "sourceKey": "domain-specialist",
              "sourceStakeholderId": "domain-specialist",
              "title": "Domain Expert",
              "description": "Brings deep knowledge of the business domain, concepts, rules, and constraints the capability or interface must reflect.",
              "involvement": "core",
              "responsibilities": [
                {
                  "resourceId": "domainCanvas",
                  "resourceTitle": "Domain Canvas",
                  "canvasId": "domainCanvas",
                  "role": "suggested-answer-owner"
                }
              ]
            },
            {
              "id": "api-consumer-specialist",
              "sourceKey": "api-consumer-specialist",
              "sourceStakeholderId": "api-consumer-specialist",
              "title": "API Consumer Representative",
              "description": "Represents the needs of developers, integrators, or other API consumers who use the API directly.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "api-devrel-specialist",
              "sourceKey": "api-devrel-specialist",
              "sourceStakeholderId": "api-devrel-specialist",
              "title": "Documentation and DevRel Owner",
              "description": "Owns onboarding content, developer communication, and documentation quality for API consumers.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "platform-architect",
              "sourceKey": "platform-architect",
              "sourceStakeholderId": "platform-architect",
              "title": "Platform Architect",
              "description": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
              "involvement": "lead",
              "responsibilities": []
            },
            {
              "id": "api-architect",
              "sourceKey": "api-architect",
              "sourceStakeholderId": "api-architect",
              "title": "API Architect",
              "description": "Owns API architecture, design principles, and interface contract quality.",
              "involvement": "core",
              "responsibilities": [
                {
                  "resourceId": "locationsCanvas",
                  "resourceTitle": "Location Canvas",
                  "canvasId": "locationsCanvas",
                  "role": "suggested-answer-owner"
                },
                {
                  "resourceId": "capacityCanvas",
                  "resourceTitle": "Capacity Canvas",
                  "canvasId": "capacityCanvas",
                  "role": "suggested-answer-owner"
                }
              ]
            },
            {
              "id": "compliance-specialist",
              "sourceKey": "compliance-specialist",
              "sourceStakeholderId": "compliance-specialist",
              "title": "Compliance and Legal Specialist",
              "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "security-specialist",
              "sourceKey": "security-specialist",
              "sourceStakeholderId": "security-specialist",
              "title": "Security Specialist",
              "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "operations-specialist",
              "sourceKey": "operations-specialist",
              "sourceStakeholderId": "operations-specialist",
              "title": "Support and Operations Owner",
              "description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "api-designer",
              "sourceKey": "api-designer",
              "sourceStakeholderId": "api-designer",
              "title": "API Designer",
              "description": "Shapes the interface contract, interaction model, consistency, and usability of the exposed capabilities.",
              "involvement": "lead",
              "responsibilities": []
            },
            {
              "id": "api-engineer",
              "sourceKey": "api-engineer",
              "sourceStakeholderId": "api-engineer",
              "title": "Delivery Engineer",
              "description": "Owns implementation, automation, testing, and release flow concerns needed to deliver the capability, API, or automation reliably.",
              "involvement": "lead",
              "responsibilities": []
            },
            {
              "id": "governance-specialist",
              "sourceKey": "governance-specialist",
              "sourceStakeholderId": "governance-specialist",
              "title": "API Governance Owner",
              "description": "Represents review, audit, and organization-wide governance practices for API quality and conformity.",
              "involvement": "lead",
              "responsibilities": []
            }
          ],
          "entryCriteria": [
            "api-opportunity-documented",
            "consumer-segments-identified"
          ],
          "exitCriteria": [
            "api-contract-tested",
            "api-ready-for-publishing",
            "api-documentation-ready"
          ],
          "entryCriteriaDetails": [
            {
              "id": "api-opportunity-documented",
              "title": "Capability opportunity is identified and documented.",
              "description": "Individual API opportunities are identified and documented."
            },
            {
              "id": "consumer-segments-identified",
              "title": "Consumer segments are identified.",
              "description": "API consumer segments (internal and external) are identified."
            }
          ],
          "exitCriteriaDetails": [
            {
              "id": "api-contract-tested",
              "title": "The interface contract has been validated and tested against functional and non-functional requirements.",
              "description": "The API contract is tested and meets functional and non-functional requirements."
            },
            {
              "id": "api-ready-for-publishing",
              "title": "The capability is ready to be published or released through the selected delivery mechanism.",
              "description": "The API is ready to be deployed and exposed through the intended gateways and environments."
            },
            {
              "id": "api-documentation-ready",
              "title": "Consumer-facing documentation and onboarding materials are ready.",
              "description": "Consumer-facing API documentation is complete enough for publishing and onboarding."
            }
          ],
          "questionnaireResources": [
            {
              "stationId": "api-product-strategy",
              "stationTitle": "API Product Strategy",
              "resourceId": "apiValuePropositionCanvas",
              "resourceTitle": "API Value Proposition Canvas",
              "canvasId": "apiValuePropositionCanvas",
              "suggestedAnswerOwner": {
                "id": "api-product-owner",
                "sourceKey": "api-product-owner",
                "sourceStakeholderId": "api-product-owner",
                "title": "API Product Owner",
                "description": "Drives the API opportunity, prioritization, and product-level decisions across the lifecycle.",
                "involvement": "lead",
                "responsibilities": [
                  {
                    "resourceId": "apiValuePropositionCanvas",
                    "resourceTitle": "API Value Proposition Canvas",
                    "canvasId": "apiValuePropositionCanvas",
                    "role": "suggested-answer-owner"
                  },
                  {
                    "resourceId": "apiBusinessModelCanvas",
                    "resourceTitle": "API Business Model Canvas",
                    "canvasId": "apiBusinessModelCanvas",
                    "role": "suggested-answer-owner"
                  }
                ]
              }
            },
            {
              "stationId": "api-product-strategy",
              "stationTitle": "API Product Strategy",
              "resourceId": "apiBusinessModelCanvas",
              "resourceTitle": "API Business Model Canvas",
              "canvasId": "apiBusinessModelCanvas",
              "suggestedAnswerOwner": {
                "id": "api-product-owner",
                "sourceKey": "api-product-owner",
                "sourceStakeholderId": "api-product-owner",
                "title": "API Product Owner",
                "description": "Drives the API opportunity, prioritization, and product-level decisions across the lifecycle.",
                "involvement": "lead",
                "responsibilities": [
                  {
                    "resourceId": "apiValuePropositionCanvas",
                    "resourceTitle": "API Value Proposition Canvas",
                    "canvasId": "apiValuePropositionCanvas",
                    "role": "suggested-answer-owner"
                  },
                  {
                    "resourceId": "apiBusinessModelCanvas",
                    "resourceTitle": "API Business Model Canvas",
                    "canvasId": "apiBusinessModelCanvas",
                    "role": "suggested-answer-owner"
                  }
                ]
              }
            },
            {
              "stationId": "api-product-strategy",
              "stationTitle": "API Product Strategy",
              "resourceId": "customerJourneyCanvas",
              "resourceTitle": "Customer Journey Canvas",
              "canvasId": "customerJourneyCanvas",
              "suggestedAnswerOwner": {
                "id": "business-owner",
                "sourceKey": "business-owner",
                "sourceStakeholderId": "business-owner",
                "title": "Business Owner",
                "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
                "involvement": "core",
                "responsibilities": [
                  {
                    "resourceId": "customerJourneyCanvas",
                    "resourceTitle": "Customer Journey Canvas",
                    "canvasId": "customerJourneyCanvas",
                    "role": "suggested-answer-owner"
                  }
                ]
              }
            },
            {
              "stationId": "api-product-strategy",
              "stationTitle": "API Product Strategy",
              "resourceId": "domainCanvas",
              "resourceTitle": "Domain Canvas",
              "canvasId": "domainCanvas",
              "suggestedAnswerOwner": {
                "id": "domain-specialist",
                "sourceKey": "domain-specialist",
                "sourceStakeholderId": "domain-specialist",
                "title": "Domain Expert",
                "description": "Brings deep knowledge of the business domain, concepts, rules, and constraints the capability or interface must reflect.",
                "involvement": "core",
                "responsibilities": [
                  {
                    "resourceId": "domainCanvas",
                    "resourceTitle": "Domain Canvas",
                    "canvasId": "domainCanvas",
                    "role": "suggested-answer-owner"
                  }
                ]
              }
            },
            {
              "stationId": "api-platform-architecture",
              "stationTitle": "API Platform Architecture",
              "resourceId": "locationsCanvas",
              "resourceTitle": "Location Canvas",
              "canvasId": "locationsCanvas",
              "suggestedAnswerOwner": {
                "id": "api-architect",
                "sourceKey": "api-architect",
                "sourceStakeholderId": "api-architect",
                "title": "API Architect",
                "description": "Owns API architecture, design principles, and interface contract quality.",
                "involvement": "core",
                "responsibilities": [
                  {
                    "resourceId": "locationsCanvas",
                    "resourceTitle": "Location Canvas",
                    "canvasId": "locationsCanvas",
                    "role": "suggested-answer-owner"
                  },
                  {
                    "resourceId": "capacityCanvas",
                    "resourceTitle": "Capacity Canvas",
                    "canvasId": "capacityCanvas",
                    "role": "suggested-answer-owner"
                  }
                ]
              }
            },
            {
              "stationId": "api-platform-architecture",
              "stationTitle": "API Platform Architecture",
              "resourceId": "capacityCanvas",
              "resourceTitle": "Capacity Canvas",
              "canvasId": "capacityCanvas",
              "suggestedAnswerOwner": {
                "id": "api-architect",
                "sourceKey": "api-architect",
                "sourceStakeholderId": "api-architect",
                "title": "API Architect",
                "description": "Owns API architecture, design principles, and interface contract quality.",
                "involvement": "core",
                "responsibilities": [
                  {
                    "resourceId": "locationsCanvas",
                    "resourceTitle": "Location Canvas",
                    "canvasId": "locationsCanvas",
                    "role": "suggested-answer-owner"
                  },
                  {
                    "resourceId": "capacityCanvas",
                    "resourceTitle": "Capacity Canvas",
                    "canvasId": "capacityCanvas",
                    "role": "suggested-answer-owner"
                  }
                ]
              }
            },
            {
              "stationId": "api-platform-architecture",
              "stationTitle": "API Platform Architecture",
              "resourceId": "businessImpactCanvas",
              "resourceTitle": "Business Impact Canvas",
              "canvasId": "businessImpactCanvas",
              "suggestedAnswerOwner": {
                "id": "api-product-owner",
                "sourceKey": "api-product-owner",
                "sourceStakeholderId": "api-product-owner",
                "title": "API Product Owner",
                "description": "Drives the API opportunity, prioritization, and product-level decisions across the lifecycle.",
                "involvement": "core",
                "responsibilities": [
                  {
                    "resourceId": "businessImpactCanvas",
                    "resourceTitle": "Business Impact Canvas",
                    "canvasId": "businessImpactCanvas",
                    "role": "suggested-answer-owner"
                  }
                ]
              }
            }
          ],
          "stations": [
            {
              "index": 1,
              "id": "api-product-strategy",
              "slug": "method/api-product-strategy",
              "icon": "strategy-outline",
              "title": "API Product Strategy",
              "description": "Before building anything, define your API's value, users, and business goals from day one.",
              "whyItMatters": "Many organizations think of APIs as tech projects, not products. The result? Confused consumers, poor adoption, and wasted effort.\n\nThis station helps you define your API’s purpose, target audience, and success criteria, so teams can deliver APIs that solve real problems.",
              "applyInWork": "Provide guidelines and templates for creating API business models, value propositions, and roadmaps.",
              "outcomes": [
                "A straightforward API value proposition and audience",
                "Shared language between product, design, and tech",
                "A solid pitch or case for funding/approval"
              ],
              "steps": [
                {
                  "text": "Explore the customer or partner problem you expect to solve with APIs. Map the stakeholders, ther journeys and outcomes using the Customer Journey canvas.",
                  "resourceId": "customerJourneyCanvas",
                  "resourceTitle": "Customer Journey Canvas",
                  "canvasId": "customerJourneyCanvas"
                },
                {
                  "text": "Define core entities, their attributes, and relationships to create a shared conceptual understanding across journeys and eventually APIs.",
                  "resourceId": "domainCanvas",
                  "resourceTitle": "Domain Canvas",
                  "canvasId": "domainCanvas"
                },
                {
                  "text": "Use the API Value Proposition Canvas to capture the supported business tasks and the API consumer pains, gains, and features that shape new or reusable APIs.",
                  "resourceId": "apiValuePropositionCanvas",
                  "resourceTitle": "API Value Proposition Canvas",
                  "canvasId": "apiValuePropositionCanvas"
                },
                {
                  "text": "Define the value — for users and the business with the API Business Model canvas to make your API strategy visual, shareable, and easy to validate with your API consumers at the next station.",
                  "resourceId": "apiBusinessModelCanvas",
                  "resourceTitle": "API Business Model Canvas",
                  "canvasId": "apiBusinessModelCanvas"
                }
              ],
              "questions": [
                "Explore the customer or partner problem you expect to solve with APIs. Map the stakeholders, ther journeys and outcomes using the Customer Journey canvas.",
                "Define core entities, their attributes, and relationships to create a shared conceptual understanding across journeys and eventually APIs.",
                "Use the API Value Proposition Canvas to capture the supported business tasks and the API consumer pains, gains, and features that shape new or reusable APIs.",
                "Define the value — for users and the business with the API Business Model canvas to make your API strategy visual, shareable, and easy to validate with your API consumers at the next station.",
                "Provide guidelines and templates for creating API business models, value propositions, and roadmaps.",
                "Many organizations think of APIs as tech projects, not products. The result? Confused consumers, poor adoption, and wasted effort.\n\nThis station helps you define your API’s purpose, target audience, and success criteria, so teams can deliver APIs that solve real problems."
              ],
              "criteria": [
                "metrics-feedback-available",
                "business-goals-defined",
                "market-research-done",
                "stakeholder-approval"
              ],
              "criteriaDetails": [
                {
                  "id": "metrics-feedback-available",
                  "title": "Relevant market signals, feedback, or operational insights are available to guide this capability opportunity.",
                  "description": "Relevant market signals, feedback, or operational insights are available to guide this API opportunity."
                },
                {
                  "id": "business-goals-defined",
                  "title": "Business goals are defined.",
                  "description": "Business goals are defined."
                },
                {
                  "id": "market-research-done",
                  "title": "Market research identifies capability opportunities.",
                  "description": "Market research identifies API opportunities."
                },
                {
                  "id": "stakeholder-approval",
                  "title": "Relevant stakeholders agree this capability opportunity is worth exploring and prioritizing.",
                  "description": "Relevant stakeholders agree this API opportunity is worth exploring and prioritizing."
                }
              ],
              "baseTitle": "Strategy",
              "group": "Capability Lifecycle Core Stations",
              "lifecycleStage": "strategy",
              "stakeholders": [
                {
                  "id": "api-product-owner",
                  "sourceKey": "api-product-owner",
                  "sourceStakeholderId": "api-product-owner",
                  "title": "API Product Owner",
                  "description": "Drives the API opportunity, prioritization, and product-level decisions across the lifecycle.",
                  "involvement": "lead",
                  "responsibilities": [
                    {
                      "resourceId": "apiValuePropositionCanvas",
                      "resourceTitle": "API Value Proposition Canvas",
                      "canvasId": "apiValuePropositionCanvas",
                      "role": "suggested-answer-owner"
                    },
                    {
                      "resourceId": "apiBusinessModelCanvas",
                      "resourceTitle": "API Business Model Canvas",
                      "canvasId": "apiBusinessModelCanvas",
                      "role": "suggested-answer-owner"
                    }
                  ]
                },
                {
                  "id": "business-owner",
                  "sourceKey": "business-owner",
                  "sourceStakeholderId": "business-owner",
                  "title": "Business Owner",
                  "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
                  "involvement": "core",
                  "responsibilities": [
                    {
                      "resourceId": "customerJourneyCanvas",
                      "resourceTitle": "Customer Journey Canvas",
                      "canvasId": "customerJourneyCanvas",
                      "role": "suggested-answer-owner"
                    }
                  ]
                },
                {
                  "id": "customer-specialist",
                  "sourceKey": "customer-specialist",
                  "sourceStakeholderId": "customer-specialist",
                  "title": "Customer or Partner Representative",
                  "description": "Contributes the business customer or partner perspective for the journey, value, and collaboration model.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "domain-specialist",
                  "sourceKey": "domain-specialist",
                  "sourceStakeholderId": "domain-specialist",
                  "title": "Domain Expert",
                  "description": "Brings deep knowledge of the business domain, concepts, rules, and constraints the capability or interface must reflect.",
                  "involvement": "core",
                  "responsibilities": [
                    {
                      "resourceId": "domainCanvas",
                      "resourceTitle": "Domain Canvas",
                      "canvasId": "domainCanvas",
                      "role": "suggested-answer-owner"
                    }
                  ]
                },
                {
                  "id": "api-consumer-specialist",
                  "sourceKey": "api-consumer-specialist",
                  "sourceStakeholderId": "api-consumer-specialist",
                  "title": "API Consumer Representative",
                  "description": "Represents the needs of developers, integrators, or other API consumers who use the API directly.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "compliance-specialist",
                  "sourceKey": "compliance-specialist",
                  "sourceStakeholderId": "compliance-specialist",
                  "title": "Compliance and Legal Specialist",
                  "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "platform-architect",
                  "sourceKey": "platform-architect",
                  "sourceStakeholderId": "platform-architect",
                  "title": "Platform Architect",
                  "description": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "security-specialist",
                  "sourceKey": "security-specialist",
                  "sourceStakeholderId": "security-specialist",
                  "title": "Security Specialist",
                  "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
                  "involvement": "consulted",
                  "responsibilities": []
                }
              ],
              "resources": [
                {
                  "id": "customerJourneyCanvas",
                  "slug": "resources/customer-journey-canvas",
                  "title": "Customer Journey Canvas",
                  "description": "Map customer, partner, or consumer journeys to identify needs, pain points, gains, inputs, outputs, and experience expectations.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 1,
                  "outcomes": [
                    "Shared understanding of the customer, partner, or consumer journey",
                    "Needs, pain points, gains, inputs, and outputs documented",
                    "Journey evidence available for capability, requirements, and architecture decisions"
                  ],
                  "steps": [
                    "Define customer persona",
                    "Identify triggers for the journey",
                    "Describe the journey's end",
                    "Map journey steps with inputs/outputs",
                    "Identify customer pains",
                    "Summarize customer gains",
                    "Define necessary inputs and resulting outputs",
                    "Define interactions and processing expectations for each step"
                  ],
                  "canvasId": "customerJourneyCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "domainCanvas",
                  "slug": "resources/domain-canvas",
                  "title": "Domain Canvas",
                  "description": "A modeling tool to define and communicate the key entities and relationships in your domain, ensuring semantic consistency across capabilities, integrations, APIs, data products, and services.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 152,
                  "outcomes": [
                    "Shared domain model and terminology",
                    "Core entities, relationships, rules, and ownership clarified",
                    "Semantic consistency across capabilities, integrations, APIs, data products, and services"
                  ],
                  "steps": [
                    "Define core entities, their attributes, and relationships to create a shared conceptual understanding across capabilities, integrations, APIs, data products, and services."
                  ],
                  "canvasId": "domainCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "apiValuePropositionCanvas",
                  "slug": "resources/api-value-proposition-canvas",
                  "title": "API Value Proposition Canvas",
                  "description": "Align API features with user needs by mapping tasks, pains, and gains to API products.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 2,
                  "outcomes": [
                    "Focused feature development",
                    "Alignment with user needs",
                    "Improved API consumer satisfaction"
                  ],
                  "steps": [
                    "List user journey tasks",
                    "Identify features delivering expected gains",
                    "Define features addressing challenges",
                    "Map features to API products"
                  ],
                  "canvasId": "apiValuePropositionCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "apiBusinessModelCanvas",
                  "slug": "resources/api-business-model-canvas",
                  "title": "API Business Model Canvas",
                  "description": "Strategically assess API business viability by mapping value propositions, consumer segments, and key resources.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 3,
                  "outcomes": [
                    "Clear business strategy for APIs",
                    "Identification of key resources and partners",
                    "Alignment of API features with business goals"
                  ],
                  "steps": [
                    "Summarize the API's value proposition",
                    "Define consumer segments",
                    "Identify developer relations strategies",
                    "Map distribution channels",
                    "Document key resources and activities",
                    "Identify key partners and stakeholders",
                    "Highlight benefits and costs"
                  ],
                  "canvasId": "apiBusinessModelCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                }
              ],
              "evidence": [
                "design-artifact",
                "documentation",
                "research",
                "roadmap"
              ]
            },
            {
              "index": 2,
              "id": "api-consumer-experience",
              "slug": "method/api-consumer-experience",
              "icon": "deployed-code-account-outline",
              "title": "API Consumer Experience",
              "description": "Ensure your API is discoverable, understandable, and usable — before and after launch.",
              "whyItMatters": "Great APIs don’t just work — they feel intuitive. Whether your consumer is an internal developer, external partner, or AI agent, their experience determines adoption.\n\nWithout a clear experience plan:\n- Great APIs go unused\n- Teams waste time guessing how to use your API\n- Feedback loops are broken or missing.\n\nThis station helps you see your API through the eyes of its consumers.",
              "applyInWork": "Provide guidelines, tools, and feedback mechanisms for understanding, analyzing, and improving internal and external developer and partner experience.",
              "outcomes": [
                "Identify and prioritize your API consumers",
                "Define the API experience journey",
                "Plan onboarding, documentation, and feedback",
                "Improve adoption through genuine empathy + Developer Experience (DX)"
              ],
              "steps": [
                {
                  "text": "Review the existing API Value Proposition Canvas from the API consumer perspective. Keep the supported business tasks stable, and enrich the pain-relieving and gain-enabling features with API consumer concerns so they can guide later design decisions.",
                  "resourceId": "apiValuePropositionCanvas",
                  "resourceTitle": "API Value Proposition Canvas",
                  "canvasId": "apiValuePropositionCanvas"
                },
                {
                  "text": "Use the Customer Journey Canvas for the API consumer journey from discovery and evaluation to onboarding, integration, troubleshooting, and ongoing use.",
                  "resourceId": "customerJourneyCanvas",
                  "resourceTitle": "Customer Journey Canvas",
                  "canvasId": "customerJourneyCanvas"
                },
                {
                  "text": "Use the resulting journey to improve onboarding, documentation, support, and feedback loops for the API consumer.",
                  "resourceId": "api-onboarding-best-practices",
                  "resourceTitle": "API Onboarding Best Practices",
                  "canvasId": null
                }
              ],
              "questions": [
                "Review the existing API Value Proposition Canvas from the API consumer perspective. Keep the supported business tasks stable, and enrich the pain-relieving and gain-enabling features with API consumer concerns so they can guide later design decisions.",
                "Use the Customer Journey Canvas for the API consumer journey from discovery and evaluation to onboarding, integration, troubleshooting, and ongoing use.",
                "Use the resulting journey to improve onboarding, documentation, support, and feedback loops for the API consumer.",
                "Provide guidelines, tools, and feedback mechanisms for understanding, analyzing, and improving internal and external developer and partner experience.",
                "Great APIs don’t just work — they feel intuitive. Whether your consumer is an internal developer, external partner, or AI agent, their experience determines adoption.\n\nWithout a clear experience plan:\n- Great APIs go unused\n- Teams waste time guessing how to use your API\n- Feedback loops are broken or missing.\n\nThis station helps you see your API through the eyes of its consumers."
              ],
              "criteria": [
                "api-opportunity-documented",
                "api-reusability",
                "hide-backend-discrepancies",
                "value-prop-validated",
                "consumer-segments-identified",
                "api-roadmap-defined"
              ],
              "criteriaDetails": [
                {
                  "id": "api-opportunity-documented",
                  "title": "Capability opportunity is identified and documented.",
                  "description": "Individual API opportunities are identified and documented."
                },
                {
                  "id": "api-reusability",
                  "title": "The capability addresses a clear business need and is reusable by its intended consumers.",
                  "description": "The API meets a clear business need and is reusable for multiple API consumers."
                },
                {
                  "id": "hide-backend-discrepancies",
                  "title": "The selected interface provides an appropriate abstraction for consumers.",
                  "description": "The API is intended to shield consumers from backend complexity and inconsistencies."
                },
                {
                  "id": "value-prop-validated",
                  "title": "The capability value proposition has been validated with business and consumer stakeholders.",
                  "description": "The API value proposition has been reviewed and validated with the relevant business and consumer stakeholders."
                },
                {
                  "id": "consumer-segments-identified",
                  "title": "Consumer segments are identified.",
                  "description": "API consumer segments (internal and external) are identified."
                },
                {
                  "id": "api-roadmap-defined",
                  "title": "A high-level implementation roadmap is defined.",
                  "description": "High-level roadmaps for API development are established."
                }
              ],
              "baseTitle": "Consumer Requirements & Onboarding",
              "group": "Capability Lifecycle Core Stations",
              "lifecycleStage": "strategy",
              "stakeholders": [
                {
                  "id": "api-product-owner",
                  "sourceKey": "api-product-owner",
                  "sourceStakeholderId": "api-product-owner",
                  "title": "API Product Owner",
                  "description": "Drives the API opportunity, prioritization, and product-level decisions across the lifecycle.",
                  "involvement": "lead",
                  "responsibilities": []
                },
                {
                  "id": "api-consumer-specialist",
                  "sourceKey": "api-consumer-specialist",
                  "sourceStakeholderId": "api-consumer-specialist",
                  "title": "API Consumer Representative",
                  "description": "Represents the needs of developers, integrators, or other API consumers who use the API directly.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "api-devrel-specialist",
                  "sourceKey": "api-devrel-specialist",
                  "sourceStakeholderId": "api-devrel-specialist",
                  "title": "Documentation and DevRel Owner",
                  "description": "Owns onboarding content, developer communication, and documentation quality for API consumers.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "domain-specialist",
                  "sourceKey": "domain-specialist",
                  "sourceStakeholderId": "domain-specialist",
                  "title": "Domain Expert",
                  "description": "Brings deep knowledge of the business domain, concepts, rules, and constraints the capability or interface must reflect.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "api-designer",
                  "sourceKey": "api-designer",
                  "sourceStakeholderId": "api-designer",
                  "title": "API Designer",
                  "description": "Shapes the interface contract, interaction model, consistency, and usability of the exposed capabilities.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "business-owner",
                  "sourceKey": "business-owner",
                  "sourceStakeholderId": "business-owner",
                  "title": "Business Owner",
                  "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "operations-specialist",
                  "sourceKey": "operations-specialist",
                  "sourceStakeholderId": "operations-specialist",
                  "title": "Support and Operations Owner",
                  "description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
                  "involvement": "consulted",
                  "responsibilities": []
                }
              ],
              "resources": [
                {
                  "id": "apiValuePropositionCanvas",
                  "slug": "resources/api-value-proposition-canvas",
                  "title": "API Value Proposition Canvas",
                  "description": "Align API features with user needs by mapping tasks, pains, and gains to API products.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 2,
                  "outcomes": [
                    "Focused feature development",
                    "Alignment with user needs",
                    "Improved API consumer satisfaction"
                  ],
                  "steps": [
                    "List user journey tasks",
                    "Identify features delivering expected gains",
                    "Define features addressing challenges",
                    "Map features to API products"
                  ],
                  "canvasId": "apiValuePropositionCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "customerJourneyCanvas",
                  "slug": "resources/customer-journey-canvas",
                  "title": "Customer Journey Canvas",
                  "description": "Map customer, partner, or consumer journeys to identify needs, pain points, gains, inputs, outputs, and experience expectations.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 1,
                  "outcomes": [
                    "Shared understanding of the customer, partner, or consumer journey",
                    "Needs, pain points, gains, inputs, and outputs documented",
                    "Journey evidence available for capability, requirements, and architecture decisions"
                  ],
                  "steps": [
                    "Define customer persona",
                    "Identify triggers for the journey",
                    "Describe the journey's end",
                    "Map journey steps with inputs/outputs",
                    "Identify customer pains",
                    "Summarize customer gains",
                    "Define necessary inputs and resulting outputs",
                    "Define interactions and processing expectations for each step"
                  ],
                  "canvasId": "customerJourneyCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "api-onboarding-best-practices",
                  "slug": "resources/api-onboarding-best-practices",
                  "title": "API Onboarding Best Practices",
                  "description": "Best practices to streamline API consumer onboarding journeys with step-by-step registration, discovery, and first-call guidance.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 121,
                  "outcomes": [
                    "Shared understanding of the purpose and use of API Onboarding Best Practices",
                    "A consistent approach to applying API Onboarding Best Practices",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Define the API consumer journey from discovery to troubleshooting, identifying key touchpoints and pain points.",
                    "Develop onboarding processes and resources to help API consumers understand how to use APIs effectively.",
                    "Document how consumers find and use the API, including onboarding processes and registration."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                }
              ],
              "evidence": [
                "design-artifact",
                "documentation",
                "consumer-feedback"
              ]
            },
            {
              "index": 3,
              "id": "api-platform-architecture",
              "slug": "method/api-platform-architecture",
              "icon": "code-blocks-outline",
              "title": "API Platform Architecture",
              "description": "Ensure scalability, reuse, and governance across your API and platform components.",
              "whyItMatters": "When APIs scale across teams, your platform must enable governance and reuse without blocking speed. This station shows how to architect APIs for longevity, security, and efficiency.",
              "applyInWork": "Establish a scalable, secure, and compliant infrastructure for API operations. Provide guidelines on architecture best practices.",
              "outcomes": [
                "Cut redundant APIs and reduce cloud platform costs",
                "Implement consistent governance without heavy top-down control",
                "Design for internal reuse and external scalability"
              ],
              "steps": [
                {
                  "text": "The Business Impact Canvas helps to identify and mitigate risks related to API availability, security, and functionality to support informed architectural decisions.",
                  "resourceId": "businessImpactCanvas",
                  "resourceTitle": "Business Impact Canvas",
                  "canvasId": "businessImpactCanvas"
                },
                {
                  "text": "Map the regulatory, compliance, and network locations of API providers and consumers to ensure accessibility and compliance.",
                  "resourceId": "locationsCanvas",
                  "resourceTitle": "Location Canvas",
                  "canvasId": "locationsCanvas"
                },
                {
                  "text": "The Capacity Canvas aligns business transaction patterns, future consumption trends, and technical solutions to ensure API scalability and performance.It provides critical input for scaling decisions and infrastructure planning.",
                  "resourceId": "capacityCanvas",
                  "resourceTitle": "Capacity Canvas",
                  "canvasId": "capacityCanvas"
                },
                {
                  "text": "Define and monitor performance metrics (e.g., API calls, latency, error rates) and adoption metrics (e.g., NPS).",
                  "resourceId": "api-metrics-and-analytics",
                  "resourceTitle": "API Metrics And Analytics",
                  "canvasId": null
                }
              ],
              "questions": [
                "The Business Impact Canvas helps to identify and mitigate risks related to API availability, security, and functionality to support informed architectural decisions.",
                "Map the regulatory, compliance, and network locations of API providers and consumers to ensure accessibility and compliance.",
                "The Capacity Canvas aligns business transaction patterns, future consumption trends, and technical solutions to ensure API scalability and performance.It provides critical input for scaling decisions and infrastructure planning.",
                "Define and monitor performance metrics (e.g., API calls, latency, error rates) and adoption metrics (e.g., NPS).",
                "Establish a scalable, secure, and compliant infrastructure for API operations. Provide guidelines on architecture best practices.",
                "When APIs scale across teams, your platform must enable governance and reuse without blocking speed. This station shows how to architect APIs for longevity, security, and efficiency."
              ],
              "criteria": [
                "api-reusability",
                "hide-backend-discrepancies",
                "value-prop-validated",
                "consumer-segments-identified",
                "api-roadmap-defined"
              ],
              "criteriaDetails": [
                {
                  "id": "api-reusability",
                  "title": "The capability addresses a clear business need and is reusable by its intended consumers.",
                  "description": "The API meets a clear business need and is reusable for multiple API consumers."
                },
                {
                  "id": "hide-backend-discrepancies",
                  "title": "The selected interface provides an appropriate abstraction for consumers.",
                  "description": "The API is intended to shield consumers from backend complexity and inconsistencies."
                },
                {
                  "id": "value-prop-validated",
                  "title": "The capability value proposition has been validated with business and consumer stakeholders.",
                  "description": "The API value proposition has been reviewed and validated with the relevant business and consumer stakeholders."
                },
                {
                  "id": "consumer-segments-identified",
                  "title": "Consumer segments are identified.",
                  "description": "API consumer segments (internal and external) are identified."
                },
                {
                  "id": "api-roadmap-defined",
                  "title": "A high-level implementation roadmap is defined.",
                  "description": "High-level roadmaps for API development are established."
                }
              ],
              "baseTitle": "Architecture & Platform Decisions",
              "group": "Capability Lifecycle Core Stations",
              "lifecycleStage": "architecture",
              "stakeholders": [
                {
                  "id": "platform-architect",
                  "sourceKey": "platform-architect",
                  "sourceStakeholderId": "platform-architect",
                  "title": "Platform Architect",
                  "description": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
                  "involvement": "lead",
                  "responsibilities": []
                },
                {
                  "id": "api-architect",
                  "sourceKey": "api-architect",
                  "sourceStakeholderId": "api-architect",
                  "title": "API Architect",
                  "description": "Owns API architecture, design principles, and interface contract quality.",
                  "involvement": "core",
                  "responsibilities": [
                    {
                      "resourceId": "locationsCanvas",
                      "resourceTitle": "Location Canvas",
                      "canvasId": "locationsCanvas",
                      "role": "suggested-answer-owner"
                    },
                    {
                      "resourceId": "capacityCanvas",
                      "resourceTitle": "Capacity Canvas",
                      "canvasId": "capacityCanvas",
                      "role": "suggested-answer-owner"
                    }
                  ]
                },
                {
                  "id": "api-product-owner",
                  "sourceKey": "api-product-owner",
                  "sourceStakeholderId": "api-product-owner",
                  "title": "API Product Owner",
                  "description": "Drives the API opportunity, prioritization, and product-level decisions across the lifecycle.",
                  "involvement": "core",
                  "responsibilities": [
                    {
                      "resourceId": "businessImpactCanvas",
                      "resourceTitle": "Business Impact Canvas",
                      "canvasId": "businessImpactCanvas",
                      "role": "suggested-answer-owner"
                    }
                  ]
                },
                {
                  "id": "compliance-specialist",
                  "sourceKey": "compliance-specialist",
                  "sourceStakeholderId": "compliance-specialist",
                  "title": "Compliance and Legal Specialist",
                  "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "domain-specialist",
                  "sourceKey": "domain-specialist",
                  "sourceStakeholderId": "domain-specialist",
                  "title": "Domain Expert",
                  "description": "Brings deep knowledge of the business domain, concepts, rules, and constraints the capability or interface must reflect.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "security-specialist",
                  "sourceKey": "security-specialist",
                  "sourceStakeholderId": "security-specialist",
                  "title": "Security Specialist",
                  "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "operations-specialist",
                  "sourceKey": "operations-specialist",
                  "sourceStakeholderId": "operations-specialist",
                  "title": "Support and Operations Owner",
                  "description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "api-consumer-specialist",
                  "sourceKey": "api-consumer-specialist",
                  "sourceStakeholderId": "api-consumer-specialist",
                  "title": "API Consumer Representative",
                  "description": "Represents the needs of developers, integrators, or other API consumers who use the API directly.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "business-owner",
                  "sourceKey": "business-owner",
                  "sourceStakeholderId": "business-owner",
                  "title": "Business Owner",
                  "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "api-engineer",
                  "sourceKey": "api-engineer",
                  "sourceStakeholderId": "api-engineer",
                  "title": "Delivery Engineer",
                  "description": "Owns implementation, automation, testing, and release flow concerns needed to deliver the capability, API, or automation reliably.",
                  "involvement": "consulted",
                  "responsibilities": []
                }
              ],
              "resources": [
                {
                  "id": "businessImpactCanvas",
                  "slug": "resources/business-impact-canvas",
                  "title": "Business Impact Canvas",
                  "description": "Identify business, availability, security, data, compliance, and operational risks that should shape architecture and platform decisions.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 4,
                  "outcomes": [
                    "Documented business and operational impact assessment",
                    "Prioritized risks and mitigation actions",
                    "Evidence for architecture and platform decisions"
                  ],
                  "steps": [
                    "Availability Risks: Identify risks and impacts.",
                    "Ways to Mitigate Availability Risks: Define mitigation measures.",
                    "Security Risks: Document security-related risks.",
                    "Ways to Mitigate Security Risks: Propose strategies to mitigate security risks.",
                    "Data Risks: Identify risks to data accuracy or availability.",
                    "Ways to Mitigate Data Risks: Plan strategies to address data risks."
                  ],
                  "canvasId": "businessImpactCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "locationsCanvas",
                  "slug": "resources/location-canvas",
                  "title": "Location Canvas",
                  "description": "Map consumer, producer, system, data, network, regulatory, and trust-boundary locations to ensure compliance and performance across regions.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 6,
                  "outcomes": [
                    "Documented location, residency, network, and regulatory requirements",
                    "Regional performance and accessibility constraints identified",
                    "Data residency, trust boundaries, and applicable regulations clarified"
                  ],
                  "steps": [
                    "Map locations of producers, source systems, platforms, and consumers.",
                    "Document where consumers are located.",
                    "Identify applicable regulations.",
                    "Document where data must reside.",
                    "Ensure the capability is accessible in all intended network regions.",
                    "Validate network performance across regions."
                  ],
                  "canvasId": "locationsCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "capacityCanvas",
                  "slug": "resources/capacity-canvas",
                  "title": "Capacity Canvas",
                  "description": "Plan capacity for current and future demand, including volumes, peaks, latency, availability, scaling, caching, and rate limits for the selected capability and implementation style.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 7,
                  "outcomes": [
                    "Capacity requirements aligned with expected business demand",
                    "Peak-load, availability, and growth assumptions documented",
                    "Scaling, caching, and rate-limiting decisions defined"
                  ],
                  "steps": [
                    "Document current business volumes",
                    "Forecast future consumption trends",
                    "Plan for peak load and availability requirements",
                    "Define caching and rate-limiting strategies",
                    "Propose scaling strategies"
                  ],
                  "canvasId": "capacityCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "api-metrics-and-analytics",
                  "slug": "resources/api-metrics-and-analytics",
                  "title": "API Metrics And Analytics",
                  "description": "A resource for defining, collecting, and analyzing API performance and usage data to align technical KPIs with business outcomes.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 119,
                  "outcomes": [
                    "Shared understanding of the purpose and use of API Metrics And Analytics",
                    "A consistent approach to applying API Metrics And Analytics",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Identify key performance indicators (KPIs) to measure API success against business goals.",
                    "Define and monitor performance metrics (e.g., API calls, latency, error rates) and adoption metrics (e.g., NPS).",
                    "Monitor API initiatives to ensure adherence to operating guidelines and governance practices"
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                }
              ],
              "evidence": [
                "architecture-decision",
                "documentation",
                "platform-config",
                "metrics"
              ]
            },
            {
              "index": 4,
              "id": "api-design",
              "slug": "method/api-design",
              "icon": "api",
              "title": "API Design",
              "description": "Create API designs that are consistent, reusable, and grounded in business intent and shared standards.",
              "whyItMatters": "Designing APIs is not just about naming endpoints. Good design ensures APIs are usable, consistent, and aligned with business and technical goals. Poor design leads to tight coupling, low reuse, and costly rework across teams.",
              "applyInWork": "Provide reusable design patterns, shared standards, and validation tools for API specifications. Ensure design decisions are consistent, reviewed early, and aligned with business intent.",
              "outcomes": [
                "Well-documented and consistent API designs",
                "Reusable and validated API contracts",
                "Designs aligned with domain models and interaction patterns",
                "Design traceability to business value"
              ],
              "steps": [
                {
                  "text": "Define core entities, their attributes, and relationships to create a shared conceptual understanding across APIs.",
                  "resourceId": "domainCanvas",
                  "resourceTitle": "Domain Canvas",
                  "canvasId": "domainCanvas"
                },
                {
                  "text": "Use the Interaction Canvas to define how consumers will interact with the API, ensuring it meets their needs and expectations.",
                  "resourceId": "interactionCanvas",
                  "resourceTitle": "Interaction Canvas",
                  "canvasId": "interactionCanvas"
                },
                {
                  "text": "Apply REST design patterns to create consistent, reusable API contracts that are validated with stakeholders.",
                  "resourceId": "restCanvas",
                  "resourceTitle": "REST Canvas",
                  "canvasId": "restCanvas"
                },
                {
                  "text": "Apply Event-driven design patterns to create consistent, reusable API contracts that are validated with stakeholders.",
                  "resourceId": "eventCanvas",
                  "resourceTitle": "Event Canvas",
                  "canvasId": "eventCanvas"
                },
                {
                  "text": "Apply GraphQL design patterns to create consistent, reusable API contracts that are validated with stakeholders.",
                  "resourceId": "graphqlCanvas",
                  "resourceTitle": "GraphQL Canvas",
                  "canvasId": "graphqlCanvas"
                },
                {
                  "text": "Use the design principles and API style guide to align your design decisions with shared rules and enable consistent audit validation.",
                  "resourceId": "api-design-principles",
                  "resourceTitle": "API Design Principles",
                  "canvasId": null
                },
                {
                  "text": "Apply contract-first or design-first approaches to capture and validate the API contract before implementation.",
                  "resourceId": "contract-first-design",
                  "resourceTitle": "Contract First Design",
                  "canvasId": null
                },
                {
                  "text": "Use the API Audit Checklist to ensure the API design meets functional and non-functional requirements, including security, performance, and compliance.",
                  "resourceId": "api-audit-checklist",
                  "resourceTitle": "API Audit Checklist",
                  "canvasId": null
                }
              ],
              "questions": [
                "Define core entities, their attributes, and relationships to create a shared conceptual understanding across APIs.",
                "Use the Interaction Canvas to define how consumers will interact with the API, ensuring it meets their needs and expectations.",
                "Apply REST design patterns to create consistent, reusable API contracts that are validated with stakeholders.",
                "Apply Event-driven design patterns to create consistent, reusable API contracts that are validated with stakeholders.",
                "Apply GraphQL design patterns to create consistent, reusable API contracts that are validated with stakeholders.",
                "Use the design principles and API style guide to align your design decisions with shared rules and enable consistent audit validation.",
                "Apply contract-first or design-first approaches to capture and validate the API contract before implementation.",
                "Use the API Audit Checklist to ensure the API design meets functional and non-functional requirements, including security, performance, and compliance.",
                "Provide reusable design patterns, shared standards, and validation tools for API specifications. Ensure design decisions are consistent, reviewed early, and aligned with business intent.",
                "Designing APIs is not just about naming endpoints. Good design ensures APIs are usable, consistent, and aligned with business and technical goals. Poor design leads to tight coupling, low reuse, and costly rework across teams."
              ],
              "criteria": [
                "architecture-patterns-validated",
                "hide-backend-discrepancies",
                "design-reflects-business-value",
                "api-consistency"
              ],
              "criteriaDetails": [
                {
                  "id": "architecture-patterns-validated",
                  "title": "The chosen architecture, platform, and implementation style have been validated with the relevant architecture, security, and platform stakeholders.",
                  "description": "The chosen API architecture and platform patterns have been validated with the relevant architecture, security, and platform stakeholders."
                },
                {
                  "id": "hide-backend-discrepancies",
                  "title": "The selected interface provides an appropriate abstraction for consumers.",
                  "description": "The API is intended to shield consumers from backend complexity and inconsistencies."
                },
                {
                  "id": "design-reflects-business-value",
                  "title": "The interface design and exposed capabilities trace back to business value and consumer needs.",
                  "description": "The API design and exposed capabilities clearly trace back to business value and user needs."
                },
                {
                  "id": "api-consistency",
                  "title": "The interface design follows agreed design standards and conventions.",
                  "description": "The API design follows our shared API product and design conventions."
                }
              ],
              "baseTitle": "Solution & Interface Design",
              "group": "Capability Lifecycle Core Stations",
              "lifecycleStage": "design",
              "stakeholders": [
                {
                  "id": "api-designer",
                  "sourceKey": "api-designer",
                  "sourceStakeholderId": "api-designer",
                  "title": "API Designer",
                  "description": "Shapes the interface contract, interaction model, consistency, and usability of the exposed capabilities.",
                  "involvement": "lead",
                  "responsibilities": []
                },
                {
                  "id": "api-consumer-specialist",
                  "sourceKey": "api-consumer-specialist",
                  "sourceStakeholderId": "api-consumer-specialist",
                  "title": "API Consumer Representative",
                  "description": "Represents the needs of developers, integrators, or other API consumers who use the API directly.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "api-product-owner",
                  "sourceKey": "api-product-owner",
                  "sourceStakeholderId": "api-product-owner",
                  "title": "API Product Owner",
                  "description": "Drives the API opportunity, prioritization, and product-level decisions across the lifecycle.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "compliance-specialist",
                  "sourceKey": "compliance-specialist",
                  "sourceStakeholderId": "compliance-specialist",
                  "title": "Compliance and Legal Specialist",
                  "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "domain-specialist",
                  "sourceKey": "domain-specialist",
                  "sourceStakeholderId": "domain-specialist",
                  "title": "Domain Expert",
                  "description": "Brings deep knowledge of the business domain, concepts, rules, and constraints the capability or interface must reflect.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "security-specialist",
                  "sourceKey": "security-specialist",
                  "sourceStakeholderId": "security-specialist",
                  "title": "Security Specialist",
                  "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "business-owner",
                  "sourceKey": "business-owner",
                  "sourceStakeholderId": "business-owner",
                  "title": "Business Owner",
                  "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "api-engineer",
                  "sourceKey": "api-engineer",
                  "sourceStakeholderId": "api-engineer",
                  "title": "Delivery Engineer",
                  "description": "Owns implementation, automation, testing, and release flow concerns needed to deliver the capability, API, or automation reliably.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "api-devrel-specialist",
                  "sourceKey": "api-devrel-specialist",
                  "sourceStakeholderId": "api-devrel-specialist",
                  "title": "Documentation and DevRel Owner",
                  "description": "Owns onboarding content, developer communication, and documentation quality for API consumers.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "platform-architect",
                  "sourceKey": "platform-architect",
                  "sourceStakeholderId": "platform-architect",
                  "title": "Platform Architect",
                  "description": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
                  "involvement": "consulted",
                  "responsibilities": []
                }
              ],
              "resources": [
                {
                  "id": "domainCanvas",
                  "slug": "resources/domain-canvas",
                  "title": "Domain Canvas",
                  "description": "A modeling tool to define and communicate the key entities and relationships in your domain, ensuring semantic consistency across capabilities, integrations, APIs, data products, and services.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 152,
                  "outcomes": [
                    "Shared domain model and terminology",
                    "Core entities, relationships, rules, and ownership clarified",
                    "Semantic consistency across capabilities, integrations, APIs, data products, and services"
                  ],
                  "steps": [
                    "Define core entities, their attributes, and relationships to create a shared conceptual understanding across capabilities, integrations, APIs, data products, and services."
                  ],
                  "canvasId": "domainCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "interactionCanvas",
                  "slug": "resources/interaction-canvas",
                  "title": "Interaction Canvas",
                  "description": "Define interactions, workflows, inputs, outputs, commands, queries, events, and expected responses to ensure a consistent consumer experience.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 9,
                  "outcomes": [
                    "Defined interaction model for the selected capability",
                    "Inputs, outputs, commands, queries, events, and responses clarified",
                    "Validation rules and interaction expectations agreed"
                  ],
                  "steps": [
                    "Map interactions to user, consumer, or system tasks",
                    "Define access points, operations, commands, queries, or events for each interaction",
                    "Document inputs and outputs for each interaction.",
                    "Specify validation rules and constraints",
                    "Create interaction models for CRUD, query-driven, command-driven, and event-driven interactions"
                  ],
                  "canvasId": "interactionCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "restCanvas",
                  "slug": "resources/rest-canvas",
                  "title": "REST Canvas",
                  "description": "Design APIs using RESTful principles, defining resources, verbs, and example requests and responses.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 10,
                  "outcomes": [
                    "Consistent RESTful API design",
                    "Defined resources and their interactions",
                    "Example requests and responses for clarity"
                  ],
                  "steps": [
                    "Identify key resources exposed by the API",
                    "Define the structure of the API resource model",
                    "Specify HTTP verbs used to interact with resources",
                    "Provide example requests and responses for each verb"
                  ],
                  "canvasId": "restCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "eventCanvas",
                  "slug": "resources/event-canvas",
                  "title": "Event Canvas",
                  "description": "Design event-driven interfaces and integrations by defining events, triggers, schemas, producers, consumers, and processing logic.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 12,
                  "outcomes": [
                    "Defined event-driven interaction model",
                    "Events, triggers, schemas, producers, and consumers clarified",
                    "Processing, acknowledgement, and failure expectations documented"
                  ],
                  "steps": [
                    "Identify key events in the system",
                    "Define triggers for each event",
                    "Describe event processing, state changes, and failure handling.",
                    "Specify resulting outputs or acknowledgments"
                  ],
                  "canvasId": "eventCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "graphqlCanvas",
                  "slug": "resources/graphql-canvas",
                  "title": "GraphQL Canvas",
                  "description": "Design GraphQL APIs by defining types, queries, mutations, and subscriptions.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 11,
                  "outcomes": [
                    "Structured GraphQL API design",
                    "Defined types and their relationships",
                    "Clear queries, mutations, and subscriptions"
                  ],
                  "steps": [
                    "What problems are API consumers trying to solve? What data do they need?",
                    "Define GraphQL types and their attributes: What are the core types exposed (e.g., User, Order, Product)?",
                    "Map relationships between types: How do types relate to each other in nested queries?",
                    "Specify queries for data retrieval",
                    "Define mutations for data modification: What operations will modify data (e.g., create, update, delete)?",
                    "Outline subscriptions for real-time updates",
                    "Define authentication and authorization: Who can access which fields or types?",
                    "Consider if there are any pagination, filtering, or rate-limiting constraints"
                  ],
                  "canvasId": "graphqlCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                },
                {
                  "id": "api-design-principles",
                  "slug": "resources/api-design-principles",
                  "title": "API Design Principles",
                  "description": "A concise guide to API usability, discoverability, and consistency grounded in shared design rules and real consumer needs.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 14,
                  "outcomes": [
                    "Shared understanding of the purpose and use of API Design Principles",
                    "A consistent approach to applying API Design Principles",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "**Consumer-first design:** start every APIOps cycle by gathering user goals and domain terms so APIs solve real problems.",
                    "**Consistent naming and behavior:** apply shared conventions for resources, errors and formats to make APIs predictable.",
                    "**Contract driven:** capture the interface with OpenAPI or AsyncAPI before coding to align teams and enable automation.",
                    "**Usability and discoverability:** provide clear documentation and examples so developers quickly understand how to use the API.",
                    "**Iterate safely:** evolve designs in small, versioned increments so changes do not disrupt existing consumers."
                  ],
                  "canvasId": null,
                  "sourcePath": "src/snippets/api-style-guide.json",
                  "sourceUrl": null,
                  "contentMarkdown": "{\r\n  \"guidelines\": [\r\n    {\r\n      \"id\": \"REST-CONTRACT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST implement endpoints, parameters, request bodies, response bodies, and error responses as defined in the validated OpenAPI contract.\",\r\n      \"relatedAuditItems\": [\r\n        \"spec-contains-schemas\",\r\n        \"schema-and-examples-pass\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CONTRACT-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST keep the implementation, published OpenAPI description, gateway configuration, and developer portal documentation aligned on every change.\",\r\n      \"relatedAuditItems\": [\r\n        \"docs-auto-generated\",\r\n        \"spec-auto-updated\",\r\n        \"spec-validated-on-change\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-VALIDATION-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST validate path parameters, query parameters, headers, and JSON request bodies against the OpenAPI schema before business processing.\",\r\n      \"relatedAuditItems\": [\r\n        \"mandatory-fields-specified\",\r\n        \"400-errors-specific\",\r\n        \"inputs-auto-validated\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DOMAIN-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST expose business-oriented resources and attributes rather than raw backend tables, internal service payloads, or system-specific field names.\",\r\n      \"relatedAuditItems\": [\r\n        \"hides-raw-backend-data\",\r\n        \"design-consistent\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DOMAIN-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST preserve validated meanings of entities, attributes, statuses, and source-of-truth rules across all endpoints and operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"design-consistent\",\r\n        \"general-data-uses-standard-values\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-NAMING-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST use descriptive English names for resources and attributes.\",\r\n      \"relatedAuditItems\": [\r\n        \"descriptive-english-naming\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-NAMING-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST avoid unexplained acronyms in public field and resource names.\",\r\n      \"relatedAuditItems\": [\r\n        \"field-names-avoid-acronyms\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DATA-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST use ISO date-time values with timezone information where dates are exposed.\",\r\n      \"relatedAuditItems\": [\r\n        \"dates-use-iso\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DATA-02\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API SHOULD use standard codes, controlled vocabularies, and standardized value sets where applicable.\",\r\n      \"relatedAuditItems\": [\r\n        \"general-data-uses-standard-values\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API MUST describe the business value and feature intent of each endpoint or capability.\",\r\n      \"relatedAuditItems\": [\r\n        \"endpoint-descriptions-present\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API MUST include examples for endpoints, request bodies, response bodies, and key attributes.\",\r\n      \"relatedAuditItems\": [\r\n        \"examples-present\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-03\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API SHOULD use consistent pagination, filtering, sorting, and response conventions across resources.\",\r\n      \"relatedAuditItems\": [\r\n        \"design-consistent\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-GET-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use GET for safe read-only operations and MUST NOT define a request body for GET operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-no-request-body\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-POST-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use POST for resource creation and other non-idempotent operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"post-for-create-update\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-PUT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use PUT only for full resource replacement.\",\r\n      \"relatedAuditItems\": [\r\n        \"post-for-create-update\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-DELETE-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use DELETE to remove resources.\",\r\n      \"relatedAuditItems\": [\r\n        \"delete-for-remove\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PATH-01\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"resource-modeling\",\r\n      \"requirement\": \"The REST API SHOULD keep endpoint paths shallow and avoid more than two resource or sub-resource levels unless explicitly justified.\",\r\n      \"relatedAuditItems\": [\r\n        \"paths-max-two-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-200-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 200 OK for successful reads and updates that include a response body.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-no-request-body\",\r\n        \"post-returns-200\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-201-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 201 Created and the created resource identifier when a new resource is created.\",\r\n      \"relatedAuditItems\": [\r\n        \"create-returns-identifiers\",\r\n        \"post-returns-201\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-204-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 204 No Content for successful delete operations that do not return a body.\",\r\n      \"relatedAuditItems\": [\r\n        \"delete-returns-204\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-204-02\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API SHOULD return 204 No Content for successful operations that intentionally return no response body.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-empty-returns-204\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-400-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST define 400 Bad Request responses with specific and actionable validation error information.\",\r\n      \"relatedAuditItems\": [\r\n        \"400-errors-specific\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-401-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST return 401 Unauthorized for missing or invalid credentials.\",\r\n      \"relatedAuditItems\": [\r\n        \"401-unauthorized\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-403-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST return 403 Forbidden for authenticated clients lacking sufficient permission.\",\r\n      \"relatedAuditItems\": [\r\n        \"403-forbidden\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-VERSION-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"versioning\",\r\n      \"requirement\": \"The REST API MUST define a versioning strategy before production release, and the strategy MUST be supportable by the API gateway.\",\r\n      \"relatedAuditItems\": [\r\n        \"versioning-decided\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST require authentication for protected endpoints.\",\r\n      \"relatedAuditItems\": [\r\n        \"auth-protection\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST use token-based authentication or another approved modern authentication mechanism for protected endpoints.\",\r\n      \"relatedAuditItems\": [\r\n        \"token-auth\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-03\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST enforce object-level and function-level authorization on every protected operation.\",\r\n      \"relatedAuditItems\": [\r\n        \"401-unauthorized\",\r\n        \"403-forbidden\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-04\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST mitigate OWASP API risks including broken object level authorization, broken function level authorization, injection, and unrestricted resource consumption.\",\r\n      \"relatedAuditItems\": [\r\n        \"auth-protection\",\r\n        \"rate-limits-enforced\",\r\n        \"no-sensitive-data-in-urls\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-05\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST use HTTPS or another approved encrypted protocol for all traffic.\",\r\n      \"relatedAuditItems\": [\r\n        \"uses-https\",\r\n        \"encryption-in-transit\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-06\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST NOT expose sensitive information in URLs, query strings, logs, or unnecessary response fields.\",\r\n      \"relatedAuditItems\": [\r\n        \"no-sensitive-data-in-urls\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-07\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API SHOULD use UUIDs or other non-sequential public identifiers where direct database identifiers would increase exposure risk.\",\r\n      \"relatedAuditItems\": [\r\n        \"pseudo-identifiers\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-08\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST implement CSRF protection where relevant to the authentication model and client interaction pattern.\",\r\n      \"relatedAuditItems\": [\r\n        \"csrf-protection\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CAPACITY-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"resilience-capacity\",\r\n      \"requirement\": \"The REST API MUST define and enforce rate limits, throttling, or quotas according to capacity expectations.\",\r\n      \"relatedAuditItems\": [\r\n        \"rate-limits-enforced\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CAPACITY-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"resilience-capacity\",\r\n      \"requirement\": \"The REST API MUST implement resilience controls such as timeouts, fallback behavior, and degradation handling according to business impact.\",\r\n      \"relatedAuditItems\": [\r\n        \"only-via-gateway\",\r\n        \"encryption-in-transit\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-OBS-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"observability\",\r\n      \"requirement\": \"The REST API MUST implement logs, metrics, and monitoring needed to observe validation failures, auth failures, traffic, latency, and dependency health.\",\r\n      \"relatedAuditItems\": [\r\n        \"rate-limits-enforced\",\r\n        \"message-integrity\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be published through an API management platform.\",\r\n      \"relatedAuditItems\": [\r\n        \"published-via-api-management\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be accessible only through approved API gateway paths and managed entry points.\",\r\n      \"relatedAuditItems\": [\r\n        \"only-via-gateway\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-03\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API SHOULD be visible in a developer portal with documentation generated from the contract.\",\r\n      \"relatedAuditItems\": [\r\n        \"visible-in-dev-portal\",\r\n        \"docs-auto-generated\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-04\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be published under an approved organizational domain.\",\r\n      \"relatedAuditItems\": [\r\n        \"official-domain\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-AUDIT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST validate the specification, schema, and examples on every change.\",\r\n      \"relatedAuditItems\": [\r\n        \"spec-validated-on-change\",\r\n        \"schema-and-examples-pass\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-AUDIT-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST pass concept, design, security, and production-readiness checks before release.\",\r\n      \"relatedAuditItems\": [\r\n        \"concept-items-audited\",\r\n        \"design-items-audited\"\r\n      ]\r\n    }\r\n  ]\r\n}",
                  "draft": false
                },
                {
                  "id": "contract-first-design",
                  "slug": "resources/contract-first-design",
                  "title": "Contract First Design",
                  "description": "A guideline advocating for API-first approaches using formal contracts (e.g., OpenAPI) to align stakeholders before development.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 146,
                  "outcomes": [
                    "Shared understanding of the purpose and use of Contract First Design",
                    "A consistent approach to applying Contract First Design",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Apply contract-first or design-first approaches to ensure API interface contracts are validated before implementation.",
                    "Define API interface contracts that outline the expectations, responsibilities, and usage guidelines for each API.",
                    "Use standardized formats (e.g., OpenAPI, AsyncAPI) to create machine-readable API interface contracts that are easy to share and validate."
                  ],
                  "canvasId": null,
                  "sourcePath": "src/snippets/api-contract-example.yaml",
                  "sourceUrl": null,
                  "contentMarkdown": "openapi: 3.0.3\r\ninfo:\r\n  title: Sample Catalog API\r\n  version: 1.0.0\r\n  description: |\r\n    Starter example for a read-only APIOps Cycles API.\r\n    This example keeps the contract audit-friendly and easy to extend.\r\nservers:\r\n  - url: /v1\r\n    description: Versioned API base path\r\ntags:\r\n  - name: catalog\r\n    description: Browse and search catalog items\r\npaths:\r\n  /items:\r\n    get:\r\n      tags: [catalog]\r\n      summary: List catalog items\r\n      description: Returns a paginated list of public catalog items.\r\n      operationId: listItems\r\n      parameters:\r\n        - $ref: \"#/components/parameters/searchTerm\"\r\n        - $ref: \"#/components/parameters/categoryId\"\r\n        - $ref: \"#/components/parameters/page\"\r\n        - $ref: \"#/components/parameters/pageSize\"\r\n      responses:\r\n        \"200\":\r\n          description: Item list\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemListResponse\"\r\n              examples:\r\n                default:\r\n                  value:\r\n                    data:\r\n                      - itemId: item-123\r\n                        slug: blue-widget\r\n                        name: Blue Widget\r\n                        status: published\r\n                    page:\r\n                      number: 1\r\n                      size: 20\r\n                      totalItems: 1\r\n        \"400\":\r\n          $ref: \"#/components/responses/BadRequest\"\r\n        \"429\":\r\n          $ref: \"#/components/responses/TooManyRequests\"\r\n  /items/{itemId}:\r\n    get:\r\n      tags: [catalog]\r\n      summary: Get item by id\r\n      description: Returns a single public catalog item by opaque identifier.\r\n      operationId: getItemById\r\n      parameters:\r\n        - $ref: \"#/components/parameters/itemId\"\r\n      responses:\r\n        \"200\":\r\n          description: Item details\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemDetail\"\r\n        \"400\":\r\n          $ref: \"#/components/responses/BadRequest\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\n  /items/by-slug/{slug}:\r\n    get:\r\n      tags: [catalog]\r\n      summary: Get item by slug\r\n      description: Returns a single item by public slug.\r\n      operationId: getItemBySlug\r\n      parameters:\r\n        - $ref: \"#/components/parameters/slug\"\r\n      responses:\r\n        \"200\":\r\n          description: Item details\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemDetail\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\n  /categories/{categoryId}/items:\r\n    get:\r\n      tags: [catalog]\r\n      summary: List items in category\r\n      description: Returns public items in a category.\r\n      operationId: listItemsByCategory\r\n      parameters:\r\n        - $ref: \"#/components/parameters/categoryId\"\r\n      responses:\r\n        \"200\":\r\n          description: Category item list\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemListResponse\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\ncomponents:\r\n  parameters:\r\n    itemId:\r\n      name: itemId\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9][a-z0-9-]{1,63}$\"\r\n      example: item-123\r\n    slug:\r\n      name: slug\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9]+(?:-[a-z0-9]+)*$\"\r\n      example: blue-widget\r\n    categoryId:\r\n      name: categoryId\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9][a-z0-9-]{1,63}$\"\r\n      example: home-goods\r\n    searchTerm:\r\n      name: searchTerm\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: string\r\n        minLength: 1\r\n      example: widget\r\n    page:\r\n      name: page\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: integer\r\n        minimum: 1\r\n        default: 1\r\n    pageSize:\r\n      name: pageSize\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: integer\r\n        minimum: 1\r\n        maximum: 100\r\n        default: 20\r\n  responses:\r\n    BadRequest:\r\n      description: Validation failed\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n          examples:\r\n            default:\r\n              value:\r\n                code: BAD_REQUEST\r\n                message: Invalid request\r\n    NotFound:\r\n      description: Resource not found\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n    TooManyRequests:\r\n      description: Rate limit exceeded\r\n      headers:\r\n        Retry-After:\r\n          schema:\r\n            type: integer\r\n          description: Seconds until the next allowed request.\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n  schemas:\r\n    ItemListResponse:\r\n      type: object\r\n      required: [data, page]\r\n      properties:\r\n        data:\r\n          type: array\r\n          items:\r\n            $ref: \"#/components/schemas/ItemSummary\"\r\n        page:\r\n          $ref: \"#/components/schemas/Page\"\r\n    ItemSummary:\r\n      type: object\r\n      required: [itemId, slug, name, status]\r\n      properties:\r\n        itemId:\r\n          type: string\r\n        slug:\r\n          type: string\r\n        name:\r\n          type: string\r\n        status:\r\n          type: string\r\n          enum: [published, hidden]\r\n    ItemDetail:\r\n      allOf:\r\n        - $ref: \"#/components/schemas/ItemSummary\"\r\n        - type: object\r\n          properties:\r\n            description:\r\n              type: string\r\n            categories:\r\n              type: array\r\n              items:\r\n                type: string\r\n            variants:\r\n              type: array\r\n              items:\r\n                $ref: \"#/components/schemas/Variant\"\r\n    Variant:\r\n      type: object\r\n      required: [variantId, sku, price, inventory]\r\n      properties:\r\n        variantId:\r\n          type: string\r\n        sku:\r\n          type: string\r\n        price:\r\n          $ref: \"#/components/schemas/Price\"\r\n        inventory:\r\n          $ref: \"#/components/schemas/Inventory\"\r\n    Price:\r\n      type: object\r\n      required: [amount, currency]\r\n      properties:\r\n        amount:\r\n          type: number\r\n          format: decimal\r\n        currency:\r\n          type: string\r\n          example: EUR\r\n    Inventory:\r\n      type: object\r\n      required: [available]\r\n      properties:\r\n        available:\r\n          type: integer\r\n          minimum: 0\r\n        reserved:\r\n          type: integer\r\n          minimum: 0\r\n        source:\r\n          type: string\r\n    Page:\r\n      type: object\r\n      required: [number, size, totalItems]\r\n      properties:\r\n        number:\r\n          type: integer\r\n        size:\r\n          type: integer\r\n        totalItems:\r\n          type: integer\r\n    ErrorResponse:\r\n      type: object\r\n      required: [code, message]\r\n      properties:\r\n        code:\r\n          type: string\r\n        message:\r\n          type: string\r\n",
                  "draft": true
                }
              ],
              "evidence": [
                "spec",
                "contract",
                "design-artifact",
                "documentation"
              ]
            },
            {
              "index": 5,
              "id": "api-delivery",
              "slug": "method/api-delivery",
              "icon": "code",
              "title": "API Delivery",
              "description": "Build, test, and release APIs using modern delivery pipelines and engineering best practices.",
              "whyItMatters": "Even the best API designs fail if delivery is inconsistent. This station ensures your APIs are built with quality, tested thoroughly, and deployed reliably — enabling faster iterations and greater confidence.",
              "applyInWork": "Deliver coding frameworks, libraries, and standards for API implementation. Implement CI/CD pipelines, quality assurance frameworks, and deployment automation tools.",
              "outcomes": [
                "APIs implemented using tested frameworks and patterns",
                "Reliable and automated CI/CD pipelines",
                "Functional and non-functional testing integrated",
                "Secure and compliant delivery pipelines"
              ],
              "steps": [
                {
                  "text": "Use API Development Best Practices as guidance for implementing the validated contract with established frameworks and libraries, ensuring the result is reusable and maintainable.",
                  "resourceId": "api-development-best-practices",
                  "resourceTitle": "API Development Best Practices",
                  "canvasId": null
                },
                {
                  "text": "Build the API implementation from the validated contract using established frameworks, libraries, and team standards.",
                  "resourceId": "api-development-best-practices",
                  "resourceTitle": "API Development Best Practices",
                  "canvasId": null
                },
                {
                  "text": "Test APIs for functionality, security, and performance using automated testing tools.",
                  "resourceId": "api-testing-best-practices",
                  "resourceTitle": "API Testing Best Practices",
                  "canvasId": null
                },
                {
                  "text": "Use CI/CD pipelines to automate build, test, and deployment processes, ensuring consistent quality and traceability.",
                  "resourceId": "apiops-CI-CD-for-apis",
                  "resourceTitle": "APIOps CI/CD For APIs",
                  "canvasId": null
                },
                {
                  "text": "Ensure APIs meet security and compliance requirements through automated checks and audits.",
                  "resourceId": "api-security-best-practices",
                  "resourceTitle": "API Security Best Practices",
                  "canvasId": null
                },
                {
                  "text": "Use the API Audit Checklist to ensure the API meets functional and non-functional requirements, including security, performance, and compliance.",
                  "resourceId": "api-audit-checklist",
                  "resourceTitle": "API Audit Checklist",
                  "canvasId": null
                }
              ],
              "questions": [
                "Use API Development Best Practices as guidance for implementing the validated contract with established frameworks and libraries, ensuring the result is reusable and maintainable.",
                "Build the API implementation from the validated contract using established frameworks, libraries, and team standards.",
                "Test APIs for functionality, security, and performance using automated testing tools.",
                "Use CI/CD pipelines to automate build, test, and deployment processes, ensuring consistent quality and traceability.",
                "Ensure APIs meet security and compliance requirements through automated checks and audits.",
                "Use the API Audit Checklist to ensure the API meets functional and non-functional requirements, including security, performance, and compliance.",
                "Deliver coding frameworks, libraries, and standards for API implementation. Implement CI/CD pipelines, quality assurance frameworks, and deployment automation tools.",
                "Even the best API designs fail if delivery is inconsistent. This station ensures your APIs are built with quality, tested thoroughly, and deployed reliably — enabling faster iterations and greater confidence."
              ],
              "criteria": [
                "architecture-patterns-validated",
                "hide-backend-discrepancies",
                "design-reflects-business-value",
                "api-consistency"
              ],
              "criteriaDetails": [
                {
                  "id": "architecture-patterns-validated",
                  "title": "The chosen architecture, platform, and implementation style have been validated with the relevant architecture, security, and platform stakeholders.",
                  "description": "The chosen API architecture and platform patterns have been validated with the relevant architecture, security, and platform stakeholders."
                },
                {
                  "id": "hide-backend-discrepancies",
                  "title": "The selected interface provides an appropriate abstraction for consumers.",
                  "description": "The API is intended to shield consumers from backend complexity and inconsistencies."
                },
                {
                  "id": "design-reflects-business-value",
                  "title": "The interface design and exposed capabilities trace back to business value and consumer needs.",
                  "description": "The API design and exposed capabilities clearly trace back to business value and user needs."
                },
                {
                  "id": "api-consistency",
                  "title": "The interface design follows agreed design standards and conventions.",
                  "description": "The API design follows our shared API product and design conventions."
                }
              ],
              "baseTitle": "Delivery & Operations",
              "group": "Capability Lifecycle Core Stations",
              "lifecycleStage": "delivery",
              "stakeholders": [
                {
                  "id": "api-engineer",
                  "sourceKey": "api-engineer",
                  "sourceStakeholderId": "api-engineer",
                  "title": "Delivery Engineer",
                  "description": "Owns implementation, automation, testing, and release flow concerns needed to deliver the capability, API, or automation reliably.",
                  "involvement": "lead",
                  "responsibilities": []
                },
                {
                  "id": "api-designer",
                  "sourceKey": "api-designer",
                  "sourceStakeholderId": "api-designer",
                  "title": "API Designer",
                  "description": "Shapes the interface contract, interaction model, consistency, and usability of the exposed capabilities.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "platform-architect",
                  "sourceKey": "platform-architect",
                  "sourceStakeholderId": "platform-architect",
                  "title": "Platform Architect",
                  "description": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "security-specialist",
                  "sourceKey": "security-specialist",
                  "sourceStakeholderId": "security-specialist",
                  "title": "Security Specialist",
                  "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "operations-specialist",
                  "sourceKey": "operations-specialist",
                  "sourceStakeholderId": "operations-specialist",
                  "title": "Support and Operations Owner",
                  "description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "api-product-owner",
                  "sourceKey": "api-product-owner",
                  "sourceStakeholderId": "api-product-owner",
                  "title": "API Product Owner",
                  "description": "Drives the API opportunity, prioritization, and product-level decisions across the lifecycle.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "business-owner",
                  "sourceKey": "business-owner",
                  "sourceStakeholderId": "business-owner",
                  "title": "Business Owner",
                  "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "compliance-specialist",
                  "sourceKey": "compliance-specialist",
                  "sourceStakeholderId": "compliance-specialist",
                  "title": "Compliance and Legal Specialist",
                  "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
                  "involvement": "consulted",
                  "responsibilities": []
                }
              ],
              "resources": [
                {
                  "id": "api-development-best-practices",
                  "slug": "resources/api-development-best-practices",
                  "title": "API Development Best Practices",
                  "description": "Implementation guidance for turning a validated API interface contract into a consistent, maintainable API codebase using standard libraries, reusable patterns, and aligned development workflows.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 112,
                  "outcomes": [
                    "Shared understanding of the purpose and use of API Development Best Practices",
                    "A consistent approach to applying API Development Best Practices",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Apply these practices to the validated API interface contract and implementation plan before coding begins.",
                    "Use established frameworks, libraries, and coding standards to implement the contract consistently and maintainably."
                  ],
                  "canvasId": null,
                  "sourcePath": "src/snippets/api-design-principles-guidance.md",
                  "sourceUrl": null,
                  "contentMarkdown": "## How to start the API Delivery work based on the previous phases (\"stations\")\r\n\r\nUse this guidance at the start of `API Delivery` after the API contract (e.g. OpenAPI) and the key outputs from earlier stations have been reviewed and accepted.\r\n\r\nThe goal is not to invent implementation in isolation. The goal is to turn the agreed outputs from earlier stations into concrete code structure, validation rules, runtime behavior, and API product delivery decisions.\r\n\r\n---\r\n\r\n### 1. Start From The Validated Contract\r\n\r\n- Treat the validated API contract as the main reference point for implementation decisions.\r\n- Keep the contract and implementation aligned throughout the API product delivery.\r\n- Use the contract to drive request validation, response mapping, documentation, and tests.\r\n\r\n---\r\n\r\n### 2. Use Domain Outputs To Preserve Business Meaning\r\n\r\n- Use the `Domain Canvas` outputs to guide naming, how the implementation is split into clear business responsibilities, and how different backend systems are connected without exposing their differences.\r\n- Preserve the validated meanings of entities, attributes, statuses, and source-of-truth rules.\r\n- Avoid leaking backend-specific models or inconsistencies into the public API.\r\n\r\n---\r\n\r\n### 3. Use Journey Outputs To Preserve Critical Flows\r\n\r\n- Use the `Customer Journey Canvas` outputs to identify which user flows are most important to support first.\r\n- Use the `API Consumer Experience` outputs to keep the API understandable, predictable, and easy to integrate.\r\n- Let the agreed journey priorities decide which implementation paths need the highest reliability, lowest latency, clearest errors, and strongest operational focus.\r\n\r\n---\r\n\r\n### 4. Use Value Proposition Outputs To Preserve Consumer Value\r\n\r\n- Use the `API Value Proposition Canvas` outputs to keep the implementation focused on the agreed pains, gains, and API features.\r\n- Preserve the field meanings, behavior, and promises that made the API valuable in the earlier stations.\r\n- Ensure error handling, freshness, and naming support both the intended developer experience and the business use case.\r\n\r\n---\r\n\r\n### 5. Use Architecture Outputs To Shape Runtime Decisions\r\n\r\n- Use the `Business Impact Canvas` outputs to guide resilience, timeout, fallback, and degradation decisions.\r\n- Use the `Locations Canvas` outputs to guide network boundaries, trust boundaries, access paths, and deployment constraints.\r\n- Use the `Capacity Canvas` outputs to guide rate limits, caching, scaling, and peak-load behavior.\r\n- Use the `API Metrics And Analytics` guidance to decide what must be observed from the first implementation onward.\r\n\r\n---\r\n\r\n### 6. Use Interaction And Protocol Design Outputs To Shape Code Structure\r\n\r\n- Use the `Interaction Canvas` outputs to avoid implementing unsupported interaction styles too early.\r\n- Use the `REST`, `Event`, or `GraphQL` design outputs to shape protocol-specific request, response, and validation behavior.\r\n- Reflect the selected interaction style clearly in code structure, responsibilities, and testing strategy.\r\n\r\n---\r\n\r\n### 7. Use Audit Outputs To Improve Delivery Before Coding Goes Too Far\r\n\r\n- Use the audit findings to remove ambiguity before implementation spreads across the codebase.\r\n- Fix unclear request rules, missing validation, weak error contracts, and operational gaps early.\r\n- Treat audit as a design-improvement loop before production, not only as a final decision gate.\r\n\r\n---\r\n\r\n### 8. Apply The Guidance, Then Summarize\r\n\r\n- Apply this guidance to the current API and implementation plan.\r\n- Summarize the implications for code structure, request validation, source integration, security, monitoring and alerts, and testing.\r\n- Do not create a separate delivery artifact unless the team or user specifically needs one.\r\n",
                  "draft": true
                },
                {
                  "id": "api-testing-best-practices",
                  "slug": "resources/api-testing-best-practices",
                  "title": "API Testing Best Practices",
                  "description": "Guidelines for implementing automated functional, performance, and security testing throughout the API lifecycle.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 133,
                  "outcomes": [
                    "Shared understanding of the purpose and use of API Testing Best Practices",
                    "A consistent approach to applying API Testing Best Practices",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Test APIs for functionality, security, and performance using automated testing tools.",
                    "Integrate functional and non-functional testing into the CI/CD pipeline to ensure APIs meet quality standards.",
                    "Use automated testing tools to validate API functionality, security, and performance."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                },
                {
                  "id": "apiops-CI-CD-for-apis",
                  "slug": "resources/apiops-CI-CD-for-apis",
                  "title": "APIOps CI/CD For APIs",
                  "description": "Deployment guidance that integrates API lifecycle tasks—design, testing, governance—into continuous integration and delivery pipelines.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 140,
                  "outcomes": [
                    "Shared understanding of the purpose and use of APIOps CI/CD For APIs",
                    "A consistent approach to applying APIOps CI/CD For APIs",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Use CI/CD pipelines to automate build, test, and deployment processes, ensuring consistent quality and traceability.",
                    "Integrate automated tests into the CI/CD pipeline to ensure continuous validation of API quality.",
                    "Implement deployment strategies (e.g., blue-green deployments, canary releases) to minimize risks during API releases.",
                    "Establish a habit of reviewing metrics and planning continuous improvement activities."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                },
                {
                  "id": "api-security-best-practices",
                  "slug": "resources/api-security-best-practices",
                  "title": "API Security Best Practices",
                  "description": "A set of actionable controls for securing APIs, including authentication, authorization, encryption, rate-limiting, and pipeline-level compliance checks.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 130,
                  "outcomes": [
                    "Shared understanding of the purpose and use of API Security Best Practices",
                    "A consistent approach to applying API Security Best Practices",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Ensure APIs meet security and compliance requirements through automated checks and audits.",
                    "Implement security measures such as authentication, authorization, encryption, and rate limiting to protect APIs from threats.",
                    "Implement automated security checks and compliance validations in the CI/CD pipeline to ensure APIs are secure and compliant."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                }
              ],
              "evidence": [
                "implementation",
                "pipeline-config",
                "test-report",
                "security-report"
              ]
            },
            {
              "index": 6,
              "id": "api-audit",
              "slug": "method/api-audit",
              "icon": "check-box-outline",
              "title": "API Audit",
              "description": "Validate that APIs meet business, design, and operational standards before release.",
              "whyItMatters": "APIs are long-lived products and must meet expectations for quality, consistency, and compliance. The audit connects design decisions, implementation, and operational readiness to defined standards, reducing risk before exposure.",
              "applyInWork": "Establish a consistent audit process that evaluates API readiness across lifecycle stages using defined criteria, evidence, and standards. Ensure gaps are identified early and resolved before release.",
              "outcomes": [
                "APIs meet internal and external standards",
                "Clear documentation of API design and implementation decisions",
                "Security, performance, and compliance validated",
                "Reduced risk of issues in production"
              ],
              "steps": [
                {
                  "text": "Conduct audits to ensure APIs meet organizational, technical, and legal standards before release.",
                  "resourceId": "api-audit-checklist",
                  "resourceTitle": "API Audit Checklist",
                  "canvasId": null
                },
                {
                  "text": "Use checklists, linters, and testing tools to verify consistency and conformance with standards.",
                  "resourceId": "api-compliance-best-practices",
                  "resourceTitle": "API Compliance Best Practices",
                  "canvasId": null
                },
                {
                  "text": "Collaborate with governance teams and domain experts to ensure APIs are ready for production.",
                  "resourceTitle": "",
                  "canvasId": null
                }
              ],
              "questions": [
                "Conduct audits to ensure APIs meet organizational, technical, and legal standards before release.",
                "Use checklists, linters, and testing tools to verify consistency and conformance with standards.",
                "Collaborate with governance teams and domain experts to ensure APIs are ready for production.",
                "Establish a consistent audit process that evaluates API readiness across lifecycle stages using defined criteria, evidence, and standards. Ensure gaps are identified early and resolved before release.",
                "APIs are long-lived products and must meet expectations for quality, consistency, and compliance. The audit connects design decisions, implementation, and operational readiness to defined standards, reducing risk before exposure."
              ],
              "criteria": [
                "architecture-patterns-validated",
                "design-reflects-business-value",
                "api-description-available",
                "api-consistency",
                "api-contract-tested"
              ],
              "criteriaDetails": [
                {
                  "id": "architecture-patterns-validated",
                  "title": "The chosen architecture, platform, and implementation style have been validated with the relevant architecture, security, and platform stakeholders.",
                  "description": "The chosen API architecture and platform patterns have been validated with the relevant architecture, security, and platform stakeholders."
                },
                {
                  "id": "design-reflects-business-value",
                  "title": "The interface design and exposed capabilities trace back to business value and consumer needs.",
                  "description": "The API design and exposed capabilities clearly trace back to business value and user needs."
                },
                {
                  "id": "api-description-available",
                  "title": "The interface and its capabilities are documented clearly enough for review, audit, and onboarding.",
                  "description": "The API and its exposed capabilities are described clearly enough for review, audit, and onboarding."
                },
                {
                  "id": "api-consistency",
                  "title": "The interface design follows agreed design standards and conventions.",
                  "description": "The API design follows our shared API product and design conventions."
                },
                {
                  "id": "api-contract-tested",
                  "title": "The interface contract has been validated and tested against functional and non-functional requirements.",
                  "description": "The API contract is tested and meets functional and non-functional requirements."
                }
              ],
              "baseTitle": "Quality & Readiness Assurance",
              "group": "Capability Lifecycle Core Stations",
              "lifecycleStage": "publishing",
              "stakeholders": [
                {
                  "id": "governance-specialist",
                  "sourceKey": "governance-specialist",
                  "sourceStakeholderId": "governance-specialist",
                  "title": "API Governance Owner",
                  "description": "Represents review, audit, and organization-wide governance practices for API quality and conformity.",
                  "involvement": "lead",
                  "responsibilities": []
                },
                {
                  "id": "api-designer",
                  "sourceKey": "api-designer",
                  "sourceStakeholderId": "api-designer",
                  "title": "API Designer",
                  "description": "Shapes the interface contract, interaction model, consistency, and usability of the exposed capabilities.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "compliance-specialist",
                  "sourceKey": "compliance-specialist",
                  "sourceStakeholderId": "compliance-specialist",
                  "title": "Compliance and Legal Specialist",
                  "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "api-engineer",
                  "sourceKey": "api-engineer",
                  "sourceStakeholderId": "api-engineer",
                  "title": "Delivery Engineer",
                  "description": "Owns implementation, automation, testing, and release flow concerns needed to deliver the capability, API, or automation reliably.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "security-specialist",
                  "sourceKey": "security-specialist",
                  "sourceStakeholderId": "security-specialist",
                  "title": "Security Specialist",
                  "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "api-product-owner",
                  "sourceKey": "api-product-owner",
                  "sourceStakeholderId": "api-product-owner",
                  "title": "API Product Owner",
                  "description": "Drives the API opportunity, prioritization, and product-level decisions across the lifecycle.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "business-owner",
                  "sourceKey": "business-owner",
                  "sourceStakeholderId": "business-owner",
                  "title": "Business Owner",
                  "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "platform-architect",
                  "sourceKey": "platform-architect",
                  "sourceStakeholderId": "platform-architect",
                  "title": "Platform Architect",
                  "description": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "operations-specialist",
                  "sourceKey": "operations-specialist",
                  "sourceStakeholderId": "operations-specialist",
                  "title": "Support and Operations Owner",
                  "description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
                  "involvement": "consulted",
                  "responsibilities": []
                }
              ],
              "resources": [
                {
                  "id": "api-audit-checklist",
                  "slug": "resources/api-audit-checklist",
                  "title": "API Audit Checklist",
                  "description": "A lifecycle-based checklist to verify API readiness across design, delivery, publishing, and compliance using defined audit criteria and evidence.",
                  "category": "checklist",
                  "icon": "check-box-outline",
                  "order": 13,
                  "outcomes": [
                    "Shared understanding of the purpose and use of API Audit Checklist",
                    "A consistent approach to applying API Audit Checklist",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Use the API Audit Checklist to ensure the API design meets functional and non-functional requirements, including security, performance, and compliance.",
                    "Conduct audits to assess lifecycle coverage and verify that the API meets business, design, and operational standards.",
                    "Ensure that documentation, security models, gateway configuration, and legal requirements are clearly defined, validated, and supported by evidence."
                  ],
                  "canvasId": null,
                  "sourcePath": "src/snippets/api-audit-checklist.json",
                  "sourceUrl": null,
                  "contentMarkdown": "{\r\n  \"profiles\": {\r\n    \"read-only\": {\r\n      \"description\": \"API profile that is read-only and does not allow create, update, or delete operations.\"\r\n    },\r\n    \"full-crud\": {\r\n      \"description\": \"General API profile that allows create, update, and delete operations.\"\r\n    }\r\n  },\r\n  \"lifecycleStages\": [\r\n    {\r\n      \"id\": \"strategy\",\r\n      \"title\": \"Strategy\",\r\n      \"readinessLabel\": \"Strategy is Ready When...\",\r\n      \"order\": 1\r\n    },\r\n    {\r\n      \"id\": \"architecture\",\r\n      \"title\": \"Architecture\",\r\n      \"readinessLabel\": \"Architecture is Ready When...\",\r\n      \"order\": 2\r\n    },\r\n    {\r\n      \"id\": \"design\",\r\n      \"title\": \"Design\",\r\n      \"readinessLabel\": \"Design is Ready When...\",\r\n      \"order\": 3\r\n    },\r\n    {\r\n      \"id\": \"delivery\",\r\n      \"title\": \"Delivery\",\r\n      \"readinessLabel\": \"Delivery is Ready When...\",\r\n      \"order\": 4\r\n    },\r\n    {\r\n      \"id\": \"publishing\",\r\n      \"title\": \"Publishing\",\r\n      \"readinessLabel\": \"Publishing is Ready When...\",\r\n      \"order\": 5\r\n    },\r\n    {\r\n      \"id\": \"improving\",\r\n      \"title\": \"Improving\",\r\n      \"readinessLabel\": \"Improving is Ready When...\",\r\n      \"order\": 6\r\n    }\r\n  ],\r\n  \"stages\": [\r\n    {\r\n      \"id\": \"strategy\",\r\n      \"title\": \"Strategy\",\r\n      \"readinessLabel\": \"Strategy is Ready When...\",\r\n      \"order\": 1,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"based-on-clear-business-needs\",\r\n          \"label\": \"API is based on clear business needs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"strategy\",\r\n          \"producedByStation\": [\r\n            \"api-product-strategy\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"business-goals-defined\",\r\n            \"market-research-done\",\r\n            \"stakeholder-approval\",\r\n            \"metrics-feedback-available\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DOMAIN-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiBusinessModelCanvas\",\r\n            \"apiValuePropositionCanvas\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"design-artifact\",\r\n            \"documentation\",\r\n            \"research\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-product-strategy/apiValuePropositionCanvas.empty.json\",\r\n            \"specs/canvases/api-product-strategy/apiBusinessModelCanvas.empty.json\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"concept-items-audited\",\r\n          \"label\": \"All concept checklist items are audited\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"aggregate\",\r\n          \"check\": {\r\n            \"type\": \"stageCoverage\",\r\n            \"stageId\": \"strategy\"\r\n          },\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"strategy\",\r\n          \"producedByStation\": [\r\n            \"api-product-strategy\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"business-goals-defined\",\r\n            \"market-research-done\",\r\n            \"stakeholder-approval\",\r\n            \"metrics-feedback-available\",\r\n            \"api-opportunity-documented\",\r\n            \"api-reusability\",\r\n            \"value-prop-validated\",\r\n            \"consumer-segments-identified\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"report\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"audit/concept-review-report.json\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"architecture\",\r\n      \"title\": \"Architecture\",\r\n      \"readinessLabel\": \"Architecture is Ready When...\",\r\n      \"order\": 2,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"versioning-decided\",\r\n          \"label\": \"Versioning strategy decided and supported by gateway\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"architecture\",\r\n          \"producedByStation\": [\r\n            \"api-platform-architecture\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-roadmap-defined\",\r\n            \"api-reusability\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-VERSION-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"contract-first-design\",\r\n            \"api-versioning-best-practices\",\r\n            \"apiops-CI-CD-for-apis\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"ci-cd\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"docs/api/architecture/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"only-via-gateway\",\r\n          \"label\": \"Only accessible via API gateway\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"architecture\",\r\n          \"producedByStation\": [\r\n            \"api-platform-architecture\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-reusability\",\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-02\",\r\n            \"REST-CAPACITY-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"businessImpactCanvas\",\r\n            \"locationsCanvas\",\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"gateway-config\",\r\n            \"infra-config\",\r\n            \"security-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/architecture/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"rate-limits-enforced\",\r\n          \"label\": \"Rate limits are enforced\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"architecture\",\r\n          \"producedByStation\": [\r\n            \"api-platform-architecture\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-roadmap-defined\",\r\n            \"api-reusability\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CAPACITY-01\",\r\n            \"REST-OBS-01\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"capacityCanvas\",\r\n            \"api-security-best-practices\",\r\n            \"scalable-infrastructure-best-practices\",\r\n            \"api-metrics-and-analytics\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"gateway-config\",\r\n            \"runtime\",\r\n            \"monitoring\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-platform-architecture/capacityCanvas.empty.json\",\r\n            \"docs/api/architecture/README.md\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"design\",\r\n      \"title\": \"Design\",\r\n      \"readinessLabel\": \"Design is Ready When...\",\r\n      \"order\": 3,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"endpoint-descriptions-present\",\r\n          \"label\": \"Endpoints have business value and feature descriptions\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"operationDescriptions\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"value-prop-validated\",\r\n            \"api-opportunity-documented\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CX-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiValuePropositionCanvas\",\r\n            \"customerJourneyCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"design-artifact\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"specs/canvases/api-product-strategy/apiValuePropositionCanvas.empty.json\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"hides-raw-backend-data\",\r\n          \"label\": \"API hides raw backend data and is designed for shared use\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"hide-backend-discrepancies\",\r\n            \"design-reflects-business-value\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DOMAIN-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"interactionCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"design-artifact\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-product-strategy/domainCanvas.empty.json\",\r\n            \"specs/canvases/api-design/interactionCanvas.empty.json\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"design-consistent\",\r\n          \"label\": \"API design is consistent with other APIs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-platform-architecture\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"architecture-patterns-validated\",\r\n            \"api-reusability\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DOMAIN-02\",\r\n            \"REST-CX-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"documentation\",\r\n            \"design-artifact\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-design/restCanvas.empty.json\",\r\n            \"docs/api/design/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"descriptive-english-naming\",\r\n          \"label\": \"Data and attribute naming uses descriptive English\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"fieldNamesDescriptive\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-NAMING-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"mandatory-fields-specified\",\r\n          \"label\": \"Mandatory fields are specified\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"requiredFieldsPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-VALIDATION-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"contract\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"dates-use-iso\",\r\n          \"label\": \"Dates use ISO format with timezone\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"dateFormatTimezone\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DATA-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"general-data-uses-standard-values\",\r\n          \"label\": \"General data uses standard values\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"standardizedEnumsOrPatterns\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"design-reflects-business-value\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DATA-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"field-names-avoid-acronyms\",\r\n          \"label\": \"Field names avoid acronyms and use full words\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"avoidAcronyms\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-NAMING-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"create-returns-identifiers\",\r\n          \"label\": \"Creating new resources returns identifiers\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is read-only and does not create resources.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-201-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"paths-max-two-resources\",\r\n          \"label\": \"Endpoint paths contain max two resources or sub-resources\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"pathDepthMax\",\r\n            \"maxDepth\": 2\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PATH-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"examples-present\",\r\n          \"label\": \"Endpoints and attributes include examples\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"examplesPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CX-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"restCanvas\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"post-for-create-update\",\r\n          \"label\": \"POST is used for create or update\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose create or update operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"design-reflects-business-value\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-POST-01\",\r\n            \"REST-HTTP-PUT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"delete-for-remove\",\r\n          \"label\": \"DELETE is used to remove resources\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose delete operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-DELETE-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"get-no-request-body\",\r\n          \"label\": \"GET has no request body and returns content\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"getNoRequestBody\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-GET-01\",\r\n            \"REST-RESP-200-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"get-empty-returns-204\",\r\n          \"label\": \"GET returns 204 if response body is empty\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"The current contract returns content for all GET operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-204-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"post-returns-200\",\r\n          \"label\": \"POST returns 200 OK when updating\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose POST updates.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-200-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"post-returns-201\",\r\n          \"label\": \"POST returns 201 Created with ID on create\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose POST creates.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-201-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"delete-returns-204\",\r\n          \"label\": \"DELETE returns 204 on success\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose DELETE operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-204-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"400-errors-specific\",\r\n          \"label\": \"400 errors provide specific error information\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"errorResponsesSpecific\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-ERROR-400-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"restCanvas\",\r\n            \"api-audit-checklist\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"401-unauthorized\",\r\n          \"label\": \"401 Unauthorized for wrong credentials\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"The current public storefront contract is intentionally unauthenticated.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-ERROR-401-01\",\r\n            \"REST-SEC-01\",\r\n            \"REST-SEC-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"security-config\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"403-forbidden\",\r\n          \"label\": \"403 Forbidden for unauthorized operations\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"The current profile is public read-only and exposes no unauthorized operations.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-ERROR-403-01\",\r\n            \"REST-SEC-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"security-config\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"spec-contains-schemas\",\r\n          \"label\": \"Spec contains request and response schema\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"schemasPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CONTRACT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"contract-first-design\",\r\n            \"restCanvas\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"contract\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"pseudo-identifiers\",\r\n          \"label\": \"UUIDs or pseudo-identifiers instead of DB IDs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"opaqueIdentifiers\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"hide-backend-discrepancies\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-07\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"contract-first-design\",\r\n            \"api-security-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"no-sensitive-data-in-urls\",\r\n          \"label\": \"No sensitive data in URLs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"noSensitiveDataInPaths\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"hide-backend-discrepancies\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-06\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"contract-first-design\",\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"http-methods-match-resources\",\r\n          \"label\": \"HTTP methods only for intended resources\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"methodResourceConsistency\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-GET-01\",\r\n            \"REST-HTTP-POST-01\",\r\n            \"REST-HTTP-PUT-01\",\r\n            \"REST-HTTP-DELETE-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"delivery\",\r\n      \"title\": \"Delivery\",\r\n      \"readinessLabel\": \"Delivery is Ready When...\",\r\n      \"order\": 4,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"design-items-audited\",\r\n          \"label\": \"All prototype and design items are audited\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"aggregate\",\r\n          \"check\": {\r\n            \"type\": \"stageCoverage\",\r\n            \"stageId\": \"design\"\r\n          },\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"design-reflects-business-value\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"report\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"audit/production-readiness-review.json\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"spec-validated-on-change\",\r\n          \"label\": \"Spec validated on every change\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"validationWorkflowPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-audit-checklist\",\r\n            \"contract-first-design\",\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"api-testing-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"ci-cd\",\r\n            \"spec\",\r\n            \"test\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \".github/workflows/openapi-lint.yml\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"schema-and-examples-pass\",\r\n          \"label\": \"Schema and examples pass validation\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"examplesPassValidation\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"architecture-patterns-validated\",\r\n            \"api-contract-tested\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-01\",\r\n            \"REST-CONTRACT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"contract-first-design\",\r\n            \"api-audit-checklist\",\r\n            \"api-testing-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"test\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"uses-https\",\r\n          \"label\": \"Uses HTTPS or encrypted protocols\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-05\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"auth-protection\",\r\n          \"label\": \"Endpoints protected by authentication\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is intentionally public read-only.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-01\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"gateway-config\",\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"token-auth\",\r\n          \"label\": \"Token-based authentication\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is intentionally public read-only.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"csrf-protection\",\r\n          \"label\": \"Protected against CSRF\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is intentionally public read-only.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-08\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-development-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"code\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"inputs-auto-validated\",\r\n          \"label\": \"Inputs auto-validated by framework\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-VALIDATION-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-development-best-practices\",\r\n            \"contract-first-design\",\r\n            \"api-testing-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"code\",\r\n            \"test\",\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"docs/api/delivery/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"outputs-auto-escaped\",\r\n          \"label\": \"Outputs auto-escaped by framework\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"JSON APIs do not typically require output escaping in the same way as HTML rendering.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-development-best-practices\",\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"code\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"encryption-in-transit\",\r\n          \"label\": \"Encryption for data in transit and storage\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-05\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\",\r\n            \"api-metrics-and-analytics\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"infra-config\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"message-integrity\",\r\n          \"label\": \"Message integrity implemented\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-OBS-01\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"api-compliance-best-practices\",\r\n            \"api-metrics-and-analytics\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"monitoring\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/architecture/README.md\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"publishing\",\r\n      \"title\": \"Publishing\",\r\n      \"readinessLabel\": \"Publishing is Ready When...\",\r\n      \"order\": 5,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"published-via-api-management\",\r\n          \"label\": \"Published via API management\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"api-onboarding-best-practices\",\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"gateway-config\",\r\n            \"ci-cd\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \".github/workflows/openapi-lint.yml\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"visible-in-dev-portal\",\r\n          \"label\": \"Visible in developer portal\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-documentation-ready\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"api-community-engagement-strategies\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"documentation\",\r\n            \"runtime\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"docs-auto-generated\",\r\n          \"label\": \"Docs auto-generated from spec and schema\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\",\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-documentation-ready\",\r\n            \"api-ready-for-publishing\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CONTRACT-02\",\r\n            \"REST-PUBLISH-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"contract-first-design\",\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"api-onboarding-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"documentation\",\r\n            \"ci-cd\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"docs/api/audit/design-audit.read-only.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"spec-auto-updated\",\r\n          \"label\": \"Spec auto-updated to gateway and dev portal\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\",\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CONTRACT-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"contract-first-design\",\r\n            \"api-onboarding-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"ci-cd\",\r\n            \"gateway-config\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \".github/workflows/openapi-lint.yml\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"official-domain\",\r\n          \"label\": \"Published under official organization domain\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"documentation\",\r\n            \"runtime\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"improving\",\r\n      \"title\": \"Improving\",\r\n      \"readinessLabel\": \"Improving is Ready When...\",\r\n      \"order\": 6,\r\n      \"items\": []\r\n    }\r\n  ],\r\n  \"guidelines\": [\r\n    {\r\n      \"id\": \"REST-CONTRACT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST implement endpoints, parameters, request bodies, response bodies, and error responses as defined in the validated OpenAPI contract.\",\r\n      \"relatedAuditItems\": [\r\n        \"spec-contains-schemas\",\r\n        \"schema-and-examples-pass\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CONTRACT-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST keep the implementation, published OpenAPI description, gateway configuration, and developer portal documentation aligned on every change.\",\r\n      \"relatedAuditItems\": [\r\n        \"docs-auto-generated\",\r\n        \"spec-auto-updated\",\r\n        \"spec-validated-on-change\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-VALIDATION-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST validate path parameters, query parameters, headers, and JSON request bodies against the OpenAPI schema before business processing.\",\r\n      \"relatedAuditItems\": [\r\n        \"mandatory-fields-specified\",\r\n        \"400-errors-specific\",\r\n        \"inputs-auto-validated\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DOMAIN-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST expose business-oriented resources and attributes rather than raw backend tables, internal service payloads, or system-specific field names.\",\r\n      \"relatedAuditItems\": [\r\n        \"based-on-clear-business-needs\",\r\n        \"hides-raw-backend-data\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DOMAIN-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST preserve validated meanings of entities, attributes, statuses, and source-of-truth rules across all endpoints and operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"design-consistent\",\r\n        \"general-data-uses-standard-values\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-NAMING-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST use descriptive English names for resources and attributes.\",\r\n      \"relatedAuditItems\": [\r\n        \"descriptive-english-naming\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-NAMING-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST avoid unexplained acronyms in public field and resource names.\",\r\n      \"relatedAuditItems\": [\r\n        \"field-names-avoid-acronyms\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DATA-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST use ISO date-time values with timezone information where dates are exposed.\",\r\n      \"relatedAuditItems\": [\r\n        \"dates-use-iso\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DATA-02\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API SHOULD use standard codes, controlled vocabularies, and standardized value sets where applicable.\",\r\n      \"relatedAuditItems\": [\r\n        \"general-data-uses-standard-values\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API MUST describe the business value and feature intent of each endpoint or capability.\",\r\n      \"relatedAuditItems\": [\r\n        \"endpoint-descriptions-present\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API MUST include examples for endpoints, request bodies, response bodies, and key attributes.\",\r\n      \"relatedAuditItems\": [\r\n        \"examples-present\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-03\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API SHOULD use consistent pagination, filtering, sorting, and response conventions across resources.\",\r\n      \"relatedAuditItems\": [\r\n        \"design-consistent\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-GET-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use GET for safe read-only operations and MUST NOT define a request body for GET operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-no-request-body\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-POST-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use POST for resource creation and other non-idempotent operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"post-for-create-update\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-PUT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use PUT only for full resource replacement.\",\r\n      \"relatedAuditItems\": [\r\n        \"post-for-create-update\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-DELETE-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use DELETE to remove resources.\",\r\n      \"relatedAuditItems\": [\r\n        \"delete-for-remove\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PATH-01\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"resource-modeling\",\r\n      \"requirement\": \"The REST API SHOULD keep endpoint paths shallow and avoid more than two resource or sub-resource levels unless explicitly justified.\",\r\n      \"relatedAuditItems\": [\r\n        \"paths-max-two-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-200-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 200 OK for successful reads and updates that include a response body.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-no-request-body\",\r\n        \"post-returns-200\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-201-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 201 Created and the created resource identifier when a new resource is created.\",\r\n      \"relatedAuditItems\": [\r\n        \"create-returns-identifiers\",\r\n        \"post-returns-201\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-204-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 204 No Content for successful delete operations that do not return a body.\",\r\n      \"relatedAuditItems\": [\r\n        \"delete-returns-204\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-204-02\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API SHOULD return 204 No Content for successful operations that intentionally return no response body.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-empty-returns-204\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-400-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST define 400 Bad Request responses with specific and actionable validation error information.\",\r\n      \"relatedAuditItems\": [\r\n        \"400-errors-specific\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-401-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST return 401 Unauthorized for missing or invalid credentials.\",\r\n      \"relatedAuditItems\": [\r\n        \"401-unauthorized\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-403-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST return 403 Forbidden for authenticated clients lacking sufficient permission.\",\r\n      \"relatedAuditItems\": [\r\n        \"403-forbidden\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-VERSION-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"versioning\",\r\n      \"requirement\": \"The REST API MUST define a versioning strategy before production release, and the strategy MUST be supportable by the API gateway.\",\r\n      \"relatedAuditItems\": [\r\n        \"versioning-decided\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST require authentication for protected endpoints.\",\r\n      \"relatedAuditItems\": [\r\n        \"auth-protection\",\r\n        \"401-unauthorized\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST use token-based authentication or another approved modern authentication mechanism for protected endpoints.\",\r\n      \"relatedAuditItems\": [\r\n        \"token-auth\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-03\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST enforce object-level and function-level authorization on every protected operation.\",\r\n      \"relatedAuditItems\": [\r\n        \"401-unauthorized\",\r\n        \"403-forbidden\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-04\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST mitigate OWASP API risks including broken object level authorization, broken function level authorization, injection, and unrestricted resource consumption.\",\r\n      \"relatedAuditItems\": [\r\n        \"auth-protection\",\r\n        \"rate-limits-enforced\",\r\n        \"no-sensitive-data-in-urls\",\r\n        \"message-integrity\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-05\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST use HTTPS or another approved encrypted protocol for all traffic.\",\r\n      \"relatedAuditItems\": [\r\n        \"uses-https\",\r\n        \"encryption-in-transit\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-06\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST NOT expose sensitive information in URLs, query strings, logs, or unnecessary response fields.\",\r\n      \"relatedAuditItems\": [\r\n        \"no-sensitive-data-in-urls\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-07\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API SHOULD use UUIDs or other non-sequential public identifiers where direct database identifiers would increase exposure risk.\",\r\n      \"relatedAuditItems\": [\r\n        \"pseudo-identifiers\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-08\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST implement CSRF protection where relevant to the authentication model and client interaction pattern.\",\r\n      \"relatedAuditItems\": [\r\n        \"csrf-protection\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CAPACITY-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"resilience-capacity\",\r\n      \"requirement\": \"The REST API MUST define and enforce rate limits, throttling, or quotas according to capacity expectations.\",\r\n      \"relatedAuditItems\": [\r\n        \"rate-limits-enforced\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CAPACITY-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"resilience-capacity\",\r\n      \"requirement\": \"The REST API MUST implement resilience controls such as timeouts, fallback behavior, and degradation handling according to business impact.\",\r\n      \"relatedAuditItems\": [\r\n        \"only-via-gateway\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-OBS-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"observability\",\r\n      \"requirement\": \"The REST API MUST implement logs, metrics, and monitoring needed to observe validation failures, auth failures, traffic, latency, and dependency health.\",\r\n      \"relatedAuditItems\": [\r\n        \"rate-limits-enforced\",\r\n        \"message-integrity\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be published through an API management platform.\",\r\n      \"relatedAuditItems\": [\r\n        \"published-via-api-management\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be accessible only through approved API gateway paths and managed entry points.\",\r\n      \"relatedAuditItems\": [\r\n        \"only-via-gateway\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-03\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API SHOULD be visible in a developer portal with documentation generated from the contract.\",\r\n      \"relatedAuditItems\": [\r\n        \"visible-in-dev-portal\",\r\n        \"docs-auto-generated\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-04\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be published under an approved organizational domain.\",\r\n      \"relatedAuditItems\": [\r\n        \"official-domain\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-AUDIT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST validate the specification, schema, and examples on every change.\",\r\n      \"relatedAuditItems\": [\r\n        \"spec-validated-on-change\",\r\n        \"schema-and-examples-pass\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-AUDIT-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST pass concept, design, security, and production-readiness checks before release.\",\r\n      \"relatedAuditItems\": [\r\n        \"concept-items-audited\",\r\n        \"design-items-audited\"\r\n      ]\r\n    }\r\n  ]\r\n}\r\n",
                  "draft": false
                },
                {
                  "id": "api-compliance-best-practices",
                  "slug": "resources/api-compliance-best-practices",
                  "title": "API Compliance Best Practices",
                  "description": "Ensure APIs meet legal, regulatory, and internal compliance through documentation, controls, and automated validations.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 104,
                  "outcomes": [
                    "Shared understanding of the purpose and use of API Compliance Best Practices",
                    "A consistent approach to applying API Compliance Best Practices",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Document compliance measures and ensure they are communicated to stakeholders and consumers.",
                    "Implement measures to ensure APIs comply with these requirements, including data encryption, access controls, and audit trails.",
                    "Use checklists, linters, and testing tools to verify consistency and conformance with standards."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                }
              ],
              "evidence": [
                "audit-report",
                "compliance-report",
                "security-report",
                "test-report"
              ]
            },
            {
              "index": 7,
              "id": "api-publishing",
              "slug": "method/api-publishing",
              "icon": "deployed-code-outline",
              "title": "API Publishing",
              "description": "Expose APIs securely and clearly to the right audience with the right documentation and processes.",
              "whyItMatters": "Publishing is more than deploying — it’s about discoverability, access, and support. If APIs aren't published correctly, they won’t be used, reused, or secured effectively.",
              "applyInWork": "Enable APIs to be published to the relevant environment and have clear registration and access mechanisms (e.g., API keys, OAuth, subscription plans) depending on the API consumer segments and security and compliance requirements.",
              "outcomes": [
                "APIs published in the right environment (private, partner, public)",
                "Clear API onboarding and registration processes",
                "Documentation, security models, and policies available",
                "APIs ready for scale and governance"
              ],
              "steps": [
                {
                  "text": "Publish APIs to the appropriate gateways and environments to support reusability for multiple API consumers.",
                  "resourceId": "apiops-CI-CD-for-apis",
                  "resourceTitle": "APIOps CI/CD For APIs",
                  "canvasId": null
                },
                {
                  "text": "Document how consumers find and use the API, including onboarding processes and registration.",
                  "resourceId": "api-onboarding-best-practices",
                  "resourceTitle": "API Onboarding Best Practices",
                  "canvasId": null
                },
                {
                  "text": "Ensure security models, gateway configuration, and legal terms are clear and accessible to consumers.",
                  "resourceId": "api-audit-checklist",
                  "resourceTitle": "API Audit Checklist",
                  "canvasId": null
                }
              ],
              "questions": [
                "Publish APIs to the appropriate gateways and environments to support reusability for multiple API consumers.",
                "Document how consumers find and use the API, including onboarding processes and registration.",
                "Ensure security models, gateway configuration, and legal terms are clear and accessible to consumers.",
                "Enable APIs to be published to the relevant environment and have clear registration and access mechanisms (e.g., API keys, OAuth, subscription plans) depending on the API consumer segments and security and compliance requirements.",
                "Publishing is more than deploying — it’s about discoverability, access, and support. If APIs aren't published correctly, they won’t be used, reused, or secured effectively."
              ],
              "criteria": [
                "audit-passed",
                "audit-reports-shared",
                "api-ready-for-publishing",
                "api-documentation-ready"
              ],
              "criteriaDetails": [
                {
                  "id": "audit-passed",
                  "title": "The solution passes quality, security, compliance, and readiness checks.",
                  "description": "The API passes compliance, security, and audit checks."
                },
                {
                  "id": "audit-reports-shared",
                  "title": "Audit findings and remediation decisions are shared with the relevant stakeholders.",
                  "description": "Audit findings and remediation decisions are shared with the relevant stakeholders."
                },
                {
                  "id": "api-ready-for-publishing",
                  "title": "The capability is ready to be published or released through the selected delivery mechanism.",
                  "description": "The API is ready to be deployed and exposed through the intended gateways and environments."
                },
                {
                  "id": "api-documentation-ready",
                  "title": "Consumer-facing documentation and onboarding materials are ready.",
                  "description": "Consumer-facing API documentation is complete enough for publishing and onboarding."
                }
              ],
              "baseTitle": "Publishing & Enablement",
              "group": "Capability Lifecycle Core Stations",
              "lifecycleStage": "publishing",
              "stakeholders": [
                {
                  "id": "api-product-owner",
                  "sourceKey": "api-product-owner",
                  "sourceStakeholderId": "api-product-owner",
                  "title": "API Product Owner",
                  "description": "Drives the API opportunity, prioritization, and product-level decisions across the lifecycle.",
                  "involvement": "lead",
                  "responsibilities": []
                },
                {
                  "id": "api-consumer-specialist",
                  "sourceKey": "api-consumer-specialist",
                  "sourceStakeholderId": "api-consumer-specialist",
                  "title": "API Consumer Representative",
                  "description": "Represents the needs of developers, integrators, or other API consumers who use the API directly.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "compliance-specialist",
                  "sourceKey": "compliance-specialist",
                  "sourceStakeholderId": "compliance-specialist",
                  "title": "Compliance and Legal Specialist",
                  "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "api-devrel-specialist",
                  "sourceKey": "api-devrel-specialist",
                  "sourceStakeholderId": "api-devrel-specialist",
                  "title": "Documentation and DevRel Owner",
                  "description": "Owns onboarding content, developer communication, and documentation quality for API consumers.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "security-specialist",
                  "sourceKey": "security-specialist",
                  "sourceStakeholderId": "security-specialist",
                  "title": "Security Specialist",
                  "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "operations-specialist",
                  "sourceKey": "operations-specialist",
                  "sourceStakeholderId": "operations-specialist",
                  "title": "Support and Operations Owner",
                  "description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "business-owner",
                  "sourceKey": "business-owner",
                  "sourceStakeholderId": "business-owner",
                  "title": "Business Owner",
                  "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "api-engineer",
                  "sourceKey": "api-engineer",
                  "sourceStakeholderId": "api-engineer",
                  "title": "Delivery Engineer",
                  "description": "Owns implementation, automation, testing, and release flow concerns needed to deliver the capability, API, or automation reliably.",
                  "involvement": "consulted",
                  "responsibilities": []
                }
              ],
              "resources": [
                {
                  "id": "apiops-CI-CD-for-apis",
                  "slug": "resources/apiops-CI-CD-for-apis",
                  "title": "APIOps CI/CD For APIs",
                  "description": "Deployment guidance that integrates API lifecycle tasks—design, testing, governance—into continuous integration and delivery pipelines.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 140,
                  "outcomes": [
                    "Shared understanding of the purpose and use of APIOps CI/CD For APIs",
                    "A consistent approach to applying APIOps CI/CD For APIs",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Use CI/CD pipelines to automate build, test, and deployment processes, ensuring consistent quality and traceability.",
                    "Integrate automated tests into the CI/CD pipeline to ensure continuous validation of API quality.",
                    "Implement deployment strategies (e.g., blue-green deployments, canary releases) to minimize risks during API releases.",
                    "Establish a habit of reviewing metrics and planning continuous improvement activities."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                },
                {
                  "id": "api-onboarding-best-practices",
                  "slug": "resources/api-onboarding-best-practices",
                  "title": "API Onboarding Best Practices",
                  "description": "Best practices to streamline API consumer onboarding journeys with step-by-step registration, discovery, and first-call guidance.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 121,
                  "outcomes": [
                    "Shared understanding of the purpose and use of API Onboarding Best Practices",
                    "A consistent approach to applying API Onboarding Best Practices",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Define the API consumer journey from discovery to troubleshooting, identifying key touchpoints and pain points.",
                    "Develop onboarding processes and resources to help API consumers understand how to use APIs effectively.",
                    "Document how consumers find and use the API, including onboarding processes and registration."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                },
                {
                  "id": "api-audit-checklist",
                  "slug": "resources/api-audit-checklist",
                  "title": "API Audit Checklist",
                  "description": "A lifecycle-based checklist to verify API readiness across design, delivery, publishing, and compliance using defined audit criteria and evidence.",
                  "category": "checklist",
                  "icon": "check-box-outline",
                  "order": 13,
                  "outcomes": [
                    "Shared understanding of the purpose and use of API Audit Checklist",
                    "A consistent approach to applying API Audit Checklist",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Use the API Audit Checklist to ensure the API design meets functional and non-functional requirements, including security, performance, and compliance.",
                    "Conduct audits to assess lifecycle coverage and verify that the API meets business, design, and operational standards.",
                    "Ensure that documentation, security models, gateway configuration, and legal requirements are clearly defined, validated, and supported by evidence."
                  ],
                  "canvasId": null,
                  "sourcePath": "src/snippets/api-audit-checklist.json",
                  "sourceUrl": null,
                  "contentMarkdown": "{\r\n  \"profiles\": {\r\n    \"read-only\": {\r\n      \"description\": \"API profile that is read-only and does not allow create, update, or delete operations.\"\r\n    },\r\n    \"full-crud\": {\r\n      \"description\": \"General API profile that allows create, update, and delete operations.\"\r\n    }\r\n  },\r\n  \"lifecycleStages\": [\r\n    {\r\n      \"id\": \"strategy\",\r\n      \"title\": \"Strategy\",\r\n      \"readinessLabel\": \"Strategy is Ready When...\",\r\n      \"order\": 1\r\n    },\r\n    {\r\n      \"id\": \"architecture\",\r\n      \"title\": \"Architecture\",\r\n      \"readinessLabel\": \"Architecture is Ready When...\",\r\n      \"order\": 2\r\n    },\r\n    {\r\n      \"id\": \"design\",\r\n      \"title\": \"Design\",\r\n      \"readinessLabel\": \"Design is Ready When...\",\r\n      \"order\": 3\r\n    },\r\n    {\r\n      \"id\": \"delivery\",\r\n      \"title\": \"Delivery\",\r\n      \"readinessLabel\": \"Delivery is Ready When...\",\r\n      \"order\": 4\r\n    },\r\n    {\r\n      \"id\": \"publishing\",\r\n      \"title\": \"Publishing\",\r\n      \"readinessLabel\": \"Publishing is Ready When...\",\r\n      \"order\": 5\r\n    },\r\n    {\r\n      \"id\": \"improving\",\r\n      \"title\": \"Improving\",\r\n      \"readinessLabel\": \"Improving is Ready When...\",\r\n      \"order\": 6\r\n    }\r\n  ],\r\n  \"stages\": [\r\n    {\r\n      \"id\": \"strategy\",\r\n      \"title\": \"Strategy\",\r\n      \"readinessLabel\": \"Strategy is Ready When...\",\r\n      \"order\": 1,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"based-on-clear-business-needs\",\r\n          \"label\": \"API is based on clear business needs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"strategy\",\r\n          \"producedByStation\": [\r\n            \"api-product-strategy\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"business-goals-defined\",\r\n            \"market-research-done\",\r\n            \"stakeholder-approval\",\r\n            \"metrics-feedback-available\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DOMAIN-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiBusinessModelCanvas\",\r\n            \"apiValuePropositionCanvas\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"design-artifact\",\r\n            \"documentation\",\r\n            \"research\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-product-strategy/apiValuePropositionCanvas.empty.json\",\r\n            \"specs/canvases/api-product-strategy/apiBusinessModelCanvas.empty.json\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"concept-items-audited\",\r\n          \"label\": \"All concept checklist items are audited\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"aggregate\",\r\n          \"check\": {\r\n            \"type\": \"stageCoverage\",\r\n            \"stageId\": \"strategy\"\r\n          },\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"strategy\",\r\n          \"producedByStation\": [\r\n            \"api-product-strategy\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"business-goals-defined\",\r\n            \"market-research-done\",\r\n            \"stakeholder-approval\",\r\n            \"metrics-feedback-available\",\r\n            \"api-opportunity-documented\",\r\n            \"api-reusability\",\r\n            \"value-prop-validated\",\r\n            \"consumer-segments-identified\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"report\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"audit/concept-review-report.json\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"architecture\",\r\n      \"title\": \"Architecture\",\r\n      \"readinessLabel\": \"Architecture is Ready When...\",\r\n      \"order\": 2,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"versioning-decided\",\r\n          \"label\": \"Versioning strategy decided and supported by gateway\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"architecture\",\r\n          \"producedByStation\": [\r\n            \"api-platform-architecture\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-roadmap-defined\",\r\n            \"api-reusability\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-VERSION-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"contract-first-design\",\r\n            \"api-versioning-best-practices\",\r\n            \"apiops-CI-CD-for-apis\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"ci-cd\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"docs/api/architecture/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"only-via-gateway\",\r\n          \"label\": \"Only accessible via API gateway\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"architecture\",\r\n          \"producedByStation\": [\r\n            \"api-platform-architecture\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-reusability\",\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-02\",\r\n            \"REST-CAPACITY-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"businessImpactCanvas\",\r\n            \"locationsCanvas\",\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"gateway-config\",\r\n            \"infra-config\",\r\n            \"security-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/architecture/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"rate-limits-enforced\",\r\n          \"label\": \"Rate limits are enforced\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"architecture\",\r\n          \"producedByStation\": [\r\n            \"api-platform-architecture\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-roadmap-defined\",\r\n            \"api-reusability\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CAPACITY-01\",\r\n            \"REST-OBS-01\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"capacityCanvas\",\r\n            \"api-security-best-practices\",\r\n            \"scalable-infrastructure-best-practices\",\r\n            \"api-metrics-and-analytics\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"gateway-config\",\r\n            \"runtime\",\r\n            \"monitoring\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-platform-architecture/capacityCanvas.empty.json\",\r\n            \"docs/api/architecture/README.md\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"design\",\r\n      \"title\": \"Design\",\r\n      \"readinessLabel\": \"Design is Ready When...\",\r\n      \"order\": 3,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"endpoint-descriptions-present\",\r\n          \"label\": \"Endpoints have business value and feature descriptions\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"operationDescriptions\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"value-prop-validated\",\r\n            \"api-opportunity-documented\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CX-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiValuePropositionCanvas\",\r\n            \"customerJourneyCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"design-artifact\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"specs/canvases/api-product-strategy/apiValuePropositionCanvas.empty.json\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"hides-raw-backend-data\",\r\n          \"label\": \"API hides raw backend data and is designed for shared use\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"hide-backend-discrepancies\",\r\n            \"design-reflects-business-value\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DOMAIN-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"interactionCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"design-artifact\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-product-strategy/domainCanvas.empty.json\",\r\n            \"specs/canvases/api-design/interactionCanvas.empty.json\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"design-consistent\",\r\n          \"label\": \"API design is consistent with other APIs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-platform-architecture\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"architecture-patterns-validated\",\r\n            \"api-reusability\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DOMAIN-02\",\r\n            \"REST-CX-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"documentation\",\r\n            \"design-artifact\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-design/restCanvas.empty.json\",\r\n            \"docs/api/design/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"descriptive-english-naming\",\r\n          \"label\": \"Data and attribute naming uses descriptive English\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"fieldNamesDescriptive\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-NAMING-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"mandatory-fields-specified\",\r\n          \"label\": \"Mandatory fields are specified\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"requiredFieldsPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-VALIDATION-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"contract\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"dates-use-iso\",\r\n          \"label\": \"Dates use ISO format with timezone\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"dateFormatTimezone\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DATA-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"general-data-uses-standard-values\",\r\n          \"label\": \"General data uses standard values\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"standardizedEnumsOrPatterns\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"design-reflects-business-value\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DATA-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"field-names-avoid-acronyms\",\r\n          \"label\": \"Field names avoid acronyms and use full words\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"avoidAcronyms\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-NAMING-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"create-returns-identifiers\",\r\n          \"label\": \"Creating new resources returns identifiers\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is read-only and does not create resources.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-201-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"paths-max-two-resources\",\r\n          \"label\": \"Endpoint paths contain max two resources or sub-resources\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"pathDepthMax\",\r\n            \"maxDepth\": 2\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PATH-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"examples-present\",\r\n          \"label\": \"Endpoints and attributes include examples\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"examplesPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CX-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"restCanvas\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"post-for-create-update\",\r\n          \"label\": \"POST is used for create or update\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose create or update operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"design-reflects-business-value\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-POST-01\",\r\n            \"REST-HTTP-PUT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"delete-for-remove\",\r\n          \"label\": \"DELETE is used to remove resources\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose delete operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-DELETE-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"get-no-request-body\",\r\n          \"label\": \"GET has no request body and returns content\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"getNoRequestBody\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-GET-01\",\r\n            \"REST-RESP-200-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"get-empty-returns-204\",\r\n          \"label\": \"GET returns 204 if response body is empty\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"The current contract returns content for all GET operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-204-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"post-returns-200\",\r\n          \"label\": \"POST returns 200 OK when updating\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose POST updates.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-200-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"post-returns-201\",\r\n          \"label\": \"POST returns 201 Created with ID on create\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose POST creates.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-201-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"delete-returns-204\",\r\n          \"label\": \"DELETE returns 204 on success\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose DELETE operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-204-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"400-errors-specific\",\r\n          \"label\": \"400 errors provide specific error information\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"errorResponsesSpecific\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-ERROR-400-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"restCanvas\",\r\n            \"api-audit-checklist\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"401-unauthorized\",\r\n          \"label\": \"401 Unauthorized for wrong credentials\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"The current public storefront contract is intentionally unauthenticated.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-ERROR-401-01\",\r\n            \"REST-SEC-01\",\r\n            \"REST-SEC-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"security-config\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"403-forbidden\",\r\n          \"label\": \"403 Forbidden for unauthorized operations\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"The current profile is public read-only and exposes no unauthorized operations.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-ERROR-403-01\",\r\n            \"REST-SEC-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"security-config\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"spec-contains-schemas\",\r\n          \"label\": \"Spec contains request and response schema\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"schemasPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CONTRACT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"contract-first-design\",\r\n            \"restCanvas\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"contract\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"pseudo-identifiers\",\r\n          \"label\": \"UUIDs or pseudo-identifiers instead of DB IDs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"opaqueIdentifiers\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"hide-backend-discrepancies\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-07\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"contract-first-design\",\r\n            \"api-security-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"no-sensitive-data-in-urls\",\r\n          \"label\": \"No sensitive data in URLs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"noSensitiveDataInPaths\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"hide-backend-discrepancies\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-06\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"contract-first-design\",\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"http-methods-match-resources\",\r\n          \"label\": \"HTTP methods only for intended resources\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"methodResourceConsistency\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-GET-01\",\r\n            \"REST-HTTP-POST-01\",\r\n            \"REST-HTTP-PUT-01\",\r\n            \"REST-HTTP-DELETE-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"delivery\",\r\n      \"title\": \"Delivery\",\r\n      \"readinessLabel\": \"Delivery is Ready When...\",\r\n      \"order\": 4,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"design-items-audited\",\r\n          \"label\": \"All prototype and design items are audited\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"aggregate\",\r\n          \"check\": {\r\n            \"type\": \"stageCoverage\",\r\n            \"stageId\": \"design\"\r\n          },\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"design-reflects-business-value\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"report\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"audit/production-readiness-review.json\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"spec-validated-on-change\",\r\n          \"label\": \"Spec validated on every change\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"validationWorkflowPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-audit-checklist\",\r\n            \"contract-first-design\",\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"api-testing-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"ci-cd\",\r\n            \"spec\",\r\n            \"test\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \".github/workflows/openapi-lint.yml\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"schema-and-examples-pass\",\r\n          \"label\": \"Schema and examples pass validation\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"examplesPassValidation\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"architecture-patterns-validated\",\r\n            \"api-contract-tested\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-01\",\r\n            \"REST-CONTRACT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"contract-first-design\",\r\n            \"api-audit-checklist\",\r\n            \"api-testing-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"test\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"uses-https\",\r\n          \"label\": \"Uses HTTPS or encrypted protocols\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-05\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"auth-protection\",\r\n          \"label\": \"Endpoints protected by authentication\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is intentionally public read-only.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-01\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"gateway-config\",\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"token-auth\",\r\n          \"label\": \"Token-based authentication\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is intentionally public read-only.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"csrf-protection\",\r\n          \"label\": \"Protected against CSRF\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is intentionally public read-only.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-08\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-development-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"code\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"inputs-auto-validated\",\r\n          \"label\": \"Inputs auto-validated by framework\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-VALIDATION-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-development-best-practices\",\r\n            \"contract-first-design\",\r\n            \"api-testing-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"code\",\r\n            \"test\",\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"docs/api/delivery/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"outputs-auto-escaped\",\r\n          \"label\": \"Outputs auto-escaped by framework\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"JSON APIs do not typically require output escaping in the same way as HTML rendering.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-development-best-practices\",\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"code\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"encryption-in-transit\",\r\n          \"label\": \"Encryption for data in transit and storage\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-05\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\",\r\n            \"api-metrics-and-analytics\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"infra-config\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"message-integrity\",\r\n          \"label\": \"Message integrity implemented\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-OBS-01\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"api-compliance-best-practices\",\r\n            \"api-metrics-and-analytics\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"monitoring\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/architecture/README.md\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"publishing\",\r\n      \"title\": \"Publishing\",\r\n      \"readinessLabel\": \"Publishing is Ready When...\",\r\n      \"order\": 5,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"published-via-api-management\",\r\n          \"label\": \"Published via API management\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"api-onboarding-best-practices\",\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"gateway-config\",\r\n            \"ci-cd\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \".github/workflows/openapi-lint.yml\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"visible-in-dev-portal\",\r\n          \"label\": \"Visible in developer portal\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-documentation-ready\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"api-community-engagement-strategies\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"documentation\",\r\n            \"runtime\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"docs-auto-generated\",\r\n          \"label\": \"Docs auto-generated from spec and schema\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\",\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-documentation-ready\",\r\n            \"api-ready-for-publishing\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CONTRACT-02\",\r\n            \"REST-PUBLISH-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"contract-first-design\",\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"api-onboarding-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"documentation\",\r\n            \"ci-cd\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"docs/api/audit/design-audit.read-only.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"spec-auto-updated\",\r\n          \"label\": \"Spec auto-updated to gateway and dev portal\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\",\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CONTRACT-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"contract-first-design\",\r\n            \"api-onboarding-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"ci-cd\",\r\n            \"gateway-config\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \".github/workflows/openapi-lint.yml\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"official-domain\",\r\n          \"label\": \"Published under official organization domain\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"documentation\",\r\n            \"runtime\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"improving\",\r\n      \"title\": \"Improving\",\r\n      \"readinessLabel\": \"Improving is Ready When...\",\r\n      \"order\": 6,\r\n      \"items\": []\r\n    }\r\n  ],\r\n  \"guidelines\": [\r\n    {\r\n      \"id\": \"REST-CONTRACT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST implement endpoints, parameters, request bodies, response bodies, and error responses as defined in the validated OpenAPI contract.\",\r\n      \"relatedAuditItems\": [\r\n        \"spec-contains-schemas\",\r\n        \"schema-and-examples-pass\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CONTRACT-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST keep the implementation, published OpenAPI description, gateway configuration, and developer portal documentation aligned on every change.\",\r\n      \"relatedAuditItems\": [\r\n        \"docs-auto-generated\",\r\n        \"spec-auto-updated\",\r\n        \"spec-validated-on-change\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-VALIDATION-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST validate path parameters, query parameters, headers, and JSON request bodies against the OpenAPI schema before business processing.\",\r\n      \"relatedAuditItems\": [\r\n        \"mandatory-fields-specified\",\r\n        \"400-errors-specific\",\r\n        \"inputs-auto-validated\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DOMAIN-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST expose business-oriented resources and attributes rather than raw backend tables, internal service payloads, or system-specific field names.\",\r\n      \"relatedAuditItems\": [\r\n        \"based-on-clear-business-needs\",\r\n        \"hides-raw-backend-data\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DOMAIN-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST preserve validated meanings of entities, attributes, statuses, and source-of-truth rules across all endpoints and operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"design-consistent\",\r\n        \"general-data-uses-standard-values\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-NAMING-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST use descriptive English names for resources and attributes.\",\r\n      \"relatedAuditItems\": [\r\n        \"descriptive-english-naming\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-NAMING-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST avoid unexplained acronyms in public field and resource names.\",\r\n      \"relatedAuditItems\": [\r\n        \"field-names-avoid-acronyms\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DATA-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST use ISO date-time values with timezone information where dates are exposed.\",\r\n      \"relatedAuditItems\": [\r\n        \"dates-use-iso\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DATA-02\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API SHOULD use standard codes, controlled vocabularies, and standardized value sets where applicable.\",\r\n      \"relatedAuditItems\": [\r\n        \"general-data-uses-standard-values\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API MUST describe the business value and feature intent of each endpoint or capability.\",\r\n      \"relatedAuditItems\": [\r\n        \"endpoint-descriptions-present\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API MUST include examples for endpoints, request bodies, response bodies, and key attributes.\",\r\n      \"relatedAuditItems\": [\r\n        \"examples-present\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-03\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API SHOULD use consistent pagination, filtering, sorting, and response conventions across resources.\",\r\n      \"relatedAuditItems\": [\r\n        \"design-consistent\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-GET-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use GET for safe read-only operations and MUST NOT define a request body for GET operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-no-request-body\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-POST-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use POST for resource creation and other non-idempotent operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"post-for-create-update\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-PUT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use PUT only for full resource replacement.\",\r\n      \"relatedAuditItems\": [\r\n        \"post-for-create-update\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-DELETE-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use DELETE to remove resources.\",\r\n      \"relatedAuditItems\": [\r\n        \"delete-for-remove\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PATH-01\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"resource-modeling\",\r\n      \"requirement\": \"The REST API SHOULD keep endpoint paths shallow and avoid more than two resource or sub-resource levels unless explicitly justified.\",\r\n      \"relatedAuditItems\": [\r\n        \"paths-max-two-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-200-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 200 OK for successful reads and updates that include a response body.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-no-request-body\",\r\n        \"post-returns-200\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-201-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 201 Created and the created resource identifier when a new resource is created.\",\r\n      \"relatedAuditItems\": [\r\n        \"create-returns-identifiers\",\r\n        \"post-returns-201\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-204-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 204 No Content for successful delete operations that do not return a body.\",\r\n      \"relatedAuditItems\": [\r\n        \"delete-returns-204\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-204-02\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API SHOULD return 204 No Content for successful operations that intentionally return no response body.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-empty-returns-204\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-400-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST define 400 Bad Request responses with specific and actionable validation error information.\",\r\n      \"relatedAuditItems\": [\r\n        \"400-errors-specific\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-401-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST return 401 Unauthorized for missing or invalid credentials.\",\r\n      \"relatedAuditItems\": [\r\n        \"401-unauthorized\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-403-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST return 403 Forbidden for authenticated clients lacking sufficient permission.\",\r\n      \"relatedAuditItems\": [\r\n        \"403-forbidden\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-VERSION-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"versioning\",\r\n      \"requirement\": \"The REST API MUST define a versioning strategy before production release, and the strategy MUST be supportable by the API gateway.\",\r\n      \"relatedAuditItems\": [\r\n        \"versioning-decided\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST require authentication for protected endpoints.\",\r\n      \"relatedAuditItems\": [\r\n        \"auth-protection\",\r\n        \"401-unauthorized\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST use token-based authentication or another approved modern authentication mechanism for protected endpoints.\",\r\n      \"relatedAuditItems\": [\r\n        \"token-auth\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-03\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST enforce object-level and function-level authorization on every protected operation.\",\r\n      \"relatedAuditItems\": [\r\n        \"401-unauthorized\",\r\n        \"403-forbidden\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-04\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST mitigate OWASP API risks including broken object level authorization, broken function level authorization, injection, and unrestricted resource consumption.\",\r\n      \"relatedAuditItems\": [\r\n        \"auth-protection\",\r\n        \"rate-limits-enforced\",\r\n        \"no-sensitive-data-in-urls\",\r\n        \"message-integrity\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-05\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST use HTTPS or another approved encrypted protocol for all traffic.\",\r\n      \"relatedAuditItems\": [\r\n        \"uses-https\",\r\n        \"encryption-in-transit\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-06\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST NOT expose sensitive information in URLs, query strings, logs, or unnecessary response fields.\",\r\n      \"relatedAuditItems\": [\r\n        \"no-sensitive-data-in-urls\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-07\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API SHOULD use UUIDs or other non-sequential public identifiers where direct database identifiers would increase exposure risk.\",\r\n      \"relatedAuditItems\": [\r\n        \"pseudo-identifiers\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-08\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST implement CSRF protection where relevant to the authentication model and client interaction pattern.\",\r\n      \"relatedAuditItems\": [\r\n        \"csrf-protection\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CAPACITY-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"resilience-capacity\",\r\n      \"requirement\": \"The REST API MUST define and enforce rate limits, throttling, or quotas according to capacity expectations.\",\r\n      \"relatedAuditItems\": [\r\n        \"rate-limits-enforced\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CAPACITY-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"resilience-capacity\",\r\n      \"requirement\": \"The REST API MUST implement resilience controls such as timeouts, fallback behavior, and degradation handling according to business impact.\",\r\n      \"relatedAuditItems\": [\r\n        \"only-via-gateway\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-OBS-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"observability\",\r\n      \"requirement\": \"The REST API MUST implement logs, metrics, and monitoring needed to observe validation failures, auth failures, traffic, latency, and dependency health.\",\r\n      \"relatedAuditItems\": [\r\n        \"rate-limits-enforced\",\r\n        \"message-integrity\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be published through an API management platform.\",\r\n      \"relatedAuditItems\": [\r\n        \"published-via-api-management\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be accessible only through approved API gateway paths and managed entry points.\",\r\n      \"relatedAuditItems\": [\r\n        \"only-via-gateway\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-03\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API SHOULD be visible in a developer portal with documentation generated from the contract.\",\r\n      \"relatedAuditItems\": [\r\n        \"visible-in-dev-portal\",\r\n        \"docs-auto-generated\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-04\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be published under an approved organizational domain.\",\r\n      \"relatedAuditItems\": [\r\n        \"official-domain\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-AUDIT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST validate the specification, schema, and examples on every change.\",\r\n      \"relatedAuditItems\": [\r\n        \"spec-validated-on-change\",\r\n        \"schema-and-examples-pass\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-AUDIT-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST pass concept, design, security, and production-readiness checks before release.\",\r\n      \"relatedAuditItems\": [\r\n        \"concept-items-audited\",\r\n        \"design-items-audited\"\r\n      ]\r\n    }\r\n  ]\r\n}\r\n",
                  "draft": false
                }
              ],
              "evidence": [
                "gateway-config",
                "developer-portal",
                "documentation",
                "release-record"
              ]
            },
            {
              "index": 8,
              "id": "monitoring-and-improving",
              "slug": "method/monitoring-and-improving",
              "icon": "analytics-outline",
              "title": "API Monitoring & Improvement",
              "description": "Use metrics and feedback to track API performance and drive continuous improvement.",
              "whyItMatters": "API delivery doesn’t stop at launch. Without monitoring, teams can’t improve adoption, performance, or ROI. This station ensures APIs remain useful, secure, and evolving with business needs.",
              "applyInWork": "Set up analytics frameworks to track performance and engagement. Develop feedback loops, analytics tools, and engagement strategies for APIs.",
              "outcomes": [
                "Performance and usage metrics defined and tracked",
                "Developer feedback loops in place",
                "Issues identified and addressed continuously",
                "API iteration aligned with user needs"
              ],
              "steps": [
                {
                  "text": "Monitor performance metrics (e.g., API calls, latency, error rates) and adoption metrics (e.g., NPS).",
                  "resourceId": "api-metrics-and-analytics",
                  "resourceTitle": "API Metrics And Analytics",
                  "canvasId": null
                },
                {
                  "text": "Analyze API usage metrics and incorporate user feedback into API iterations.",
                  "resourceId": "api-community-engagement-strategies",
                  "resourceTitle": "API Community Engagement Strategies",
                  "canvasId": null
                },
                {
                  "text": "Establish a habit of reviewing metrics and planning continuous improvement activities.",
                  "resourceId": "apiops-CI-CD-for-apis",
                  "resourceTitle": "APIOps CI/CD For APIs",
                  "canvasId": null
                }
              ],
              "questions": [
                "Monitor performance metrics (e.g., API calls, latency, error rates) and adoption metrics (e.g., NPS).",
                "Analyze API usage metrics and incorporate user feedback into API iterations.",
                "Establish a habit of reviewing metrics and planning continuous improvement activities.",
                "Set up analytics frameworks to track performance and engagement. Develop feedback loops, analytics tools, and engagement strategies for APIs.",
                "API delivery doesn’t stop at launch. Without monitoring, teams can’t improve adoption, performance, or ROI. This station ensures APIs remain useful, secure, and evolving with business needs."
              ],
              "criteria": [
                "api-documentation-ready",
                "consumer-support-ready",
                "legal-compliance-clear"
              ],
              "criteriaDetails": [
                {
                  "id": "api-documentation-ready",
                  "title": "Consumer-facing documentation and onboarding materials are ready.",
                  "description": "Consumer-facing API documentation is complete enough for publishing and onboarding."
                },
                {
                  "id": "consumer-support-ready",
                  "title": "Consumer onboarding, support, and communication processes are ready.",
                  "description": "Registration, support, and communication processes are ready for API consumers."
                },
                {
                  "id": "legal-compliance-clear",
                  "title": "Legal, privacy, and compliance requirements for publishing or release are defined and understood.",
                  "description": "Legal, privacy, and compliance requirements for publishing are defined and understood."
                }
              ],
              "baseTitle": "Monitoring & Improvement",
              "group": "Capability Lifecycle Core Stations",
              "lifecycleStage": "improving",
              "stakeholders": [
                {
                  "id": "api-product-owner",
                  "sourceKey": "api-product-owner",
                  "sourceStakeholderId": "api-product-owner",
                  "title": "API Product Owner",
                  "description": "Drives the API opportunity, prioritization, and product-level decisions across the lifecycle.",
                  "involvement": "lead",
                  "responsibilities": []
                },
                {
                  "id": "api-consumer-specialist",
                  "sourceKey": "api-consumer-specialist",
                  "sourceStakeholderId": "api-consumer-specialist",
                  "title": "API Consumer Representative",
                  "description": "Represents the needs of developers, integrators, or other API consumers who use the API directly.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "business-owner",
                  "sourceKey": "business-owner",
                  "sourceStakeholderId": "business-owner",
                  "title": "Business Owner",
                  "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "api-engineer",
                  "sourceKey": "api-engineer",
                  "sourceStakeholderId": "api-engineer",
                  "title": "Delivery Engineer",
                  "description": "Owns implementation, automation, testing, and release flow concerns needed to deliver the capability, API, or automation reliably.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "api-devrel-specialist",
                  "sourceKey": "api-devrel-specialist",
                  "sourceStakeholderId": "api-devrel-specialist",
                  "title": "Documentation and DevRel Owner",
                  "description": "Owns onboarding content, developer communication, and documentation quality for API consumers.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "operations-specialist",
                  "sourceKey": "operations-specialist",
                  "sourceStakeholderId": "operations-specialist",
                  "title": "Support and Operations Owner",
                  "description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "compliance-specialist",
                  "sourceKey": "compliance-specialist",
                  "sourceStakeholderId": "compliance-specialist",
                  "title": "Compliance and Legal Specialist",
                  "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "domain-specialist",
                  "sourceKey": "domain-specialist",
                  "sourceStakeholderId": "domain-specialist",
                  "title": "Domain Expert",
                  "description": "Brings deep knowledge of the business domain, concepts, rules, and constraints the capability or interface must reflect.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "platform-architect",
                  "sourceKey": "platform-architect",
                  "sourceStakeholderId": "platform-architect",
                  "title": "Platform Architect",
                  "description": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "security-specialist",
                  "sourceKey": "security-specialist",
                  "sourceStakeholderId": "security-specialist",
                  "title": "Security Specialist",
                  "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
                  "involvement": "consulted",
                  "responsibilities": []
                }
              ],
              "resources": [
                {
                  "id": "api-metrics-and-analytics",
                  "slug": "resources/api-metrics-and-analytics",
                  "title": "API Metrics And Analytics",
                  "description": "A resource for defining, collecting, and analyzing API performance and usage data to align technical KPIs with business outcomes.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 119,
                  "outcomes": [
                    "Shared understanding of the purpose and use of API Metrics And Analytics",
                    "A consistent approach to applying API Metrics And Analytics",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Identify key performance indicators (KPIs) to measure API success against business goals.",
                    "Define and monitor performance metrics (e.g., API calls, latency, error rates) and adoption metrics (e.g., NPS).",
                    "Monitor API initiatives to ensure adherence to operating guidelines and governance practices"
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                },
                {
                  "id": "api-community-engagement-strategies",
                  "slug": "resources/api-community-engagement-strategies",
                  "title": "API Community Engagement Strategies",
                  "description": "A playbook for fostering API adoption by cultivating communities through content, support channels, feedback loops, and social engagement strategies.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 103,
                  "outcomes": [
                    "Shared understanding of the purpose and use of API Community Engagement Strategies",
                    "A consistent approach to applying API Community Engagement Strategies",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Develop marketing strategies to promote APIs to target audiences, including social media, blogs, and webinars.",
                    "Create promotional materials (e.g., case studies, success stories) that highlight the value and benefits of APIs.",
                    "Create educational materials (e.g., tutorials, documentation) that explain API features, benefits, and usage patterns.",
                    "Engage with API consumers through feedback loops, support channels, and community forums to understand their needs and improve API adoption.",
                    "Analyze API usage metrics and incorporate user feedback into API iterations."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                }
              ],
              "evidence": [
                "metrics",
                "consumer-feedback",
                "incident-report",
                "roadmap"
              ]
            }
          ]
        },
        {
          "id": "integration-productization-cycle",
          "slug": "integration-productization-cycle",
          "title": "Integration Productization Cycle",
          "description": "A cycle for productizing reusable integration capabilities before selecting the implementation style.",
          "purpose": "Guide reusable integration capability design before choosing an API, event, file, stream, data product, direct integration, or hybrid implementation style.",
          "audiences": [],
          "audienceStakeholders": [
            {
              "id": "integration-architect",
              "sourceKey": "integration-architect",
              "sourceStakeholderId": "integration-architect",
              "title": "Integration Architect",
              "description": "Designs integration approaches and implementation styles that connect the capability or API with other systems.",
              "involvement": "lead",
              "responsibilities": []
            },
            {
              "id": "business-owner",
              "sourceKey": "business-owner",
              "sourceStakeholderId": "business-owner",
              "title": "Business Owner",
              "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
              "involvement": "core",
              "responsibilities": [
                {
                  "resourceId": "customerJourneyCanvas",
                  "resourceTitle": "Customer Journey Canvas",
                  "canvasId": "customerJourneyCanvas",
                  "role": "suggested-answer-owner"
                }
              ]
            },
            {
              "id": "capability-owner",
              "sourceKey": "capability-owner",
              "sourceStakeholderId": "capability-owner",
              "title": "Capability Owner",
              "description": "Owns the capability vision, value, priorities, lifecycle, and reuse across consumers.",
              "involvement": "core",
              "responsibilities": [
                {
                  "resourceId": "capabilityValuePropositionCanvas",
                  "resourceTitle": "Capability Value Proposition Canvas",
                  "canvasId": "capabilityValuePropositionCanvas",
                  "role": "suggested-answer-owner"
                },
                {
                  "resourceId": "capabilityBusinessModelCanvas",
                  "resourceTitle": "Capability Business Model Canvas",
                  "canvasId": "capabilityBusinessModelCanvas",
                  "role": "suggested-answer-owner"
                }
              ]
            },
            {
              "id": "domain-specialist",
              "sourceKey": "domain-specialist",
              "sourceStakeholderId": "domain-specialist",
              "title": "Domain Expert",
              "description": "Brings deep knowledge of the business domain, concepts, rules, and constraints the capability or interface must reflect.",
              "involvement": "core",
              "responsibilities": [
                {
                  "resourceId": "domainCanvas",
                  "resourceTitle": "Domain Canvas",
                  "canvasId": "domainCanvas",
                  "role": "suggested-answer-owner"
                }
              ]
            },
            {
              "id": "platform-owner",
              "sourceKey": "platform-owner",
              "sourceStakeholderId": "platform-owner",
              "title": "Platform Owner",
              "description": "Owns platform capabilities, roadmap, operational model, and service expectations.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "api-consumer-specialist",
              "sourceKey": "api-consumer-specialist",
              "sourceStakeholderId": "api-consumer-specialist",
              "title": "API Consumer Representative",
              "description": "Represents the needs of developers, integrators, or other API consumers who use the API directly.",
              "involvement": "lead",
              "responsibilities": [
                {
                  "resourceId": "consumerExperienceRequirementsCanvas",
                  "resourceTitle": "Consumer Experience Requirements Canvas",
                  "canvasId": "consumerExperienceRequirementsCanvas",
                  "role": "suggested-answer-owner"
                }
              ]
            },
            {
              "id": "customer-specialist",
              "sourceKey": "customer-specialist",
              "sourceStakeholderId": "customer-specialist",
              "title": "Customer or Partner Representative",
              "description": "Contributes the business customer or partner perspective for the journey, value, and collaboration model.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "platform-architect",
              "sourceKey": "platform-architect",
              "sourceStakeholderId": "platform-architect",
              "title": "Platform Architect",
              "description": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
              "involvement": "lead",
              "responsibilities": [
                {
                  "resourceId": "locationsCanvas",
                  "resourceTitle": "Location Canvas",
                  "canvasId": "locationsCanvas",
                  "role": "suggested-answer-owner"
                }
              ]
            },
            {
              "id": "compliance-specialist",
              "sourceKey": "compliance-specialist",
              "sourceStakeholderId": "compliance-specialist",
              "title": "Compliance and Legal Specialist",
              "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "security-specialist",
              "sourceKey": "security-specialist",
              "sourceStakeholderId": "security-specialist",
              "title": "Security Specialist",
              "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "operations-specialist",
              "sourceKey": "operations-specialist",
              "sourceStakeholderId": "operations-specialist",
              "title": "Support and Operations Owner",
              "description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "api-designer",
              "sourceKey": "api-designer",
              "sourceStakeholderId": "api-designer",
              "title": "API Designer",
              "description": "Shapes the interface contract, interaction model, consistency, and usability of the exposed capabilities.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "api-engineer",
              "sourceKey": "api-engineer",
              "sourceStakeholderId": "api-engineer",
              "title": "Delivery Engineer",
              "description": "Owns implementation, automation, testing, and release flow concerns needed to deliver the capability, API, or automation reliably.",
              "involvement": "lead",
              "responsibilities": []
            },
            {
              "id": "governance-specialist",
              "sourceKey": "governance-specialist",
              "sourceStakeholderId": "governance-specialist",
              "title": "API Governance Owner",
              "description": "Represents review, audit, and organization-wide governance practices for API quality and conformity.",
              "involvement": "lead",
              "responsibilities": []
            },
            {
              "id": "api-devrel-specialist",
              "sourceKey": "api-devrel-specialist",
              "sourceStakeholderId": "api-devrel-specialist",
              "title": "Documentation and DevRel Owner",
              "description": "Owns onboarding content, developer communication, and documentation quality for API consumers.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "partner-specialist",
              "sourceKey": "partner-specialist",
              "sourceStakeholderId": "partner-specialist",
              "title": "Partner or Vendor Manager",
              "description": "Coordinates external partner, supplier, or vendor relationships that influence capability or API strategy and delivery.",
              "involvement": "core",
              "responsibilities": []
            }
          ],
          "entryCriteria": [
            "business-goals-defined",
            "api-opportunity-documented"
          ],
          "exitCriteria": [
            "architecture-patterns-validated",
            "api-description-available",
            "audit-passed"
          ],
          "entryCriteriaDetails": [
            {
              "id": "business-goals-defined",
              "title": "Business goals are defined.",
              "description": "Business goals are defined."
            },
            {
              "id": "api-opportunity-documented",
              "title": "Capability opportunity is identified and documented.",
              "description": "Individual API opportunities are identified and documented."
            }
          ],
          "exitCriteriaDetails": [
            {
              "id": "architecture-patterns-validated",
              "title": "The chosen architecture, platform, and implementation style have been validated with the relevant architecture, security, and platform stakeholders.",
              "description": "The chosen API architecture and platform patterns have been validated with the relevant architecture, security, and platform stakeholders."
            },
            {
              "id": "api-description-available",
              "title": "The interface and its capabilities are documented clearly enough for review, audit, and onboarding.",
              "description": "The API and its exposed capabilities are described clearly enough for review, audit, and onboarding."
            },
            {
              "id": "audit-passed",
              "title": "The solution passes quality, security, compliance, and readiness checks.",
              "description": "The API passes compliance, security, and audit checks."
            }
          ],
          "questionnaireResources": [
            {
              "stationId": "api-product-strategy",
              "stationTitle": "Integration Capability Strategy",
              "resourceId": "customerJourneyCanvas",
              "resourceTitle": "Customer Journey Canvas",
              "canvasId": "customerJourneyCanvas",
              "suggestedAnswerOwner": {
                "id": "business-owner",
                "sourceKey": "business-owner",
                "sourceStakeholderId": "business-owner",
                "title": "Business Owner",
                "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
                "involvement": "core",
                "responsibilities": [
                  {
                    "resourceId": "customerJourneyCanvas",
                    "resourceTitle": "Customer Journey Canvas",
                    "canvasId": "customerJourneyCanvas",
                    "role": "suggested-answer-owner"
                  }
                ]
              }
            },
            {
              "stationId": "api-product-strategy",
              "stationTitle": "Integration Capability Strategy",
              "resourceId": "capabilityValuePropositionCanvas",
              "resourceTitle": "Capability Value Proposition Canvas",
              "canvasId": "capabilityValuePropositionCanvas",
              "suggestedAnswerOwner": {
                "id": "capability-owner",
                "sourceKey": "capability-owner",
                "sourceStakeholderId": "capability-owner",
                "title": "Capability Owner",
                "description": "Owns the capability vision, value, priorities, lifecycle, and reuse across consumers.",
                "involvement": "core",
                "responsibilities": [
                  {
                    "resourceId": "capabilityValuePropositionCanvas",
                    "resourceTitle": "Capability Value Proposition Canvas",
                    "canvasId": "capabilityValuePropositionCanvas",
                    "role": "suggested-answer-owner"
                  },
                  {
                    "resourceId": "capabilityBusinessModelCanvas",
                    "resourceTitle": "Capability Business Model Canvas",
                    "canvasId": "capabilityBusinessModelCanvas",
                    "role": "suggested-answer-owner"
                  }
                ]
              }
            },
            {
              "stationId": "api-product-strategy",
              "stationTitle": "Integration Capability Strategy",
              "resourceId": "capabilityBusinessModelCanvas",
              "resourceTitle": "Capability Business Model Canvas",
              "canvasId": "capabilityBusinessModelCanvas",
              "suggestedAnswerOwner": {
                "id": "capability-owner",
                "sourceKey": "capability-owner",
                "sourceStakeholderId": "capability-owner",
                "title": "Capability Owner",
                "description": "Owns the capability vision, value, priorities, lifecycle, and reuse across consumers.",
                "involvement": "core",
                "responsibilities": [
                  {
                    "resourceId": "capabilityValuePropositionCanvas",
                    "resourceTitle": "Capability Value Proposition Canvas",
                    "canvasId": "capabilityValuePropositionCanvas",
                    "role": "suggested-answer-owner"
                  },
                  {
                    "resourceId": "capabilityBusinessModelCanvas",
                    "resourceTitle": "Capability Business Model Canvas",
                    "canvasId": "capabilityBusinessModelCanvas",
                    "role": "suggested-answer-owner"
                  }
                ]
              }
            },
            {
              "stationId": "api-product-strategy",
              "stationTitle": "Integration Capability Strategy",
              "resourceId": "domainCanvas",
              "resourceTitle": "Domain Canvas",
              "canvasId": "domainCanvas",
              "suggestedAnswerOwner": {
                "id": "domain-specialist",
                "sourceKey": "domain-specialist",
                "sourceStakeholderId": "domain-specialist",
                "title": "Domain Expert",
                "description": "Brings deep knowledge of the business domain, concepts, rules, and constraints the capability or interface must reflect.",
                "involvement": "core",
                "responsibilities": [
                  {
                    "resourceId": "domainCanvas",
                    "resourceTitle": "Domain Canvas",
                    "canvasId": "domainCanvas",
                    "role": "suggested-answer-owner"
                  }
                ]
              }
            },
            {
              "stationId": "api-consumer-experience",
              "stationTitle": "Integration Consumer Requirements & Onboarding",
              "resourceId": "consumerExperienceRequirementsCanvas",
              "resourceTitle": "Consumer Experience Requirements Canvas",
              "canvasId": "consumerExperienceRequirementsCanvas",
              "suggestedAnswerOwner": {
                "id": "api-consumer-specialist",
                "sourceKey": "api-consumer-specialist",
                "sourceStakeholderId": "api-consumer-specialist",
                "title": "API Consumer Representative",
                "description": "Represents the needs of developers, integrators, or other API consumers who use the API directly.",
                "involvement": "lead",
                "responsibilities": [
                  {
                    "resourceId": "consumerExperienceRequirementsCanvas",
                    "resourceTitle": "Consumer Experience Requirements Canvas",
                    "canvasId": "consumerExperienceRequirementsCanvas",
                    "role": "suggested-answer-owner"
                  }
                ]
              }
            },
            {
              "stationId": "api-platform-architecture",
              "stationTitle": "Integration Architecture & Platform Decisions",
              "resourceId": "locationsCanvas",
              "resourceTitle": "Location Canvas",
              "canvasId": "locationsCanvas",
              "suggestedAnswerOwner": {
                "id": "platform-architect",
                "sourceKey": "platform-architect",
                "sourceStakeholderId": "platform-architect",
                "title": "Platform Architect",
                "description": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
                "involvement": "lead",
                "responsibilities": [
                  {
                    "resourceId": "locationsCanvas",
                    "resourceTitle": "Location Canvas",
                    "canvasId": "locationsCanvas",
                    "role": "suggested-answer-owner"
                  }
                ]
              }
            },
            {
              "stationId": "api-platform-architecture",
              "stationTitle": "Integration Architecture & Platform Decisions",
              "resourceId": "businessImpactCanvas",
              "resourceTitle": "Business Impact Canvas",
              "canvasId": "businessImpactCanvas",
              "suggestedAnswerOwner": {
                "id": "integration-architect",
                "sourceKey": "integration-architect",
                "sourceStakeholderId": "integration-architect",
                "title": "Integration Architect",
                "description": "Designs integration approaches and implementation styles that connect the capability or API with other systems.",
                "involvement": "core",
                "responsibilities": [
                  {
                    "resourceId": "businessImpactCanvas",
                    "resourceTitle": "Business Impact Canvas",
                    "canvasId": "businessImpactCanvas",
                    "role": "suggested-answer-owner"
                  }
                ]
              }
            },
            {
              "stationId": "api-platform-architecture",
              "stationTitle": "Integration Architecture & Platform Decisions",
              "resourceId": "capacityCanvas",
              "resourceTitle": "Capacity Canvas",
              "canvasId": "capacityCanvas",
              "suggestedAnswerOwner": {
                "id": "platform-owner",
                "sourceKey": "platform-owner",
                "sourceStakeholderId": "platform-owner",
                "title": "Platform Owner",
                "description": "Owns platform capabilities, roadmap, operational model, and service expectations.",
                "involvement": "core",
                "responsibilities": [
                  {
                    "resourceId": "capacityCanvas",
                    "resourceTitle": "Capacity Canvas",
                    "canvasId": "capacityCanvas",
                    "role": "suggested-answer-owner"
                  }
                ]
              }
            }
          ],
          "stations": [
            {
              "index": 1,
              "id": "api-product-strategy",
              "slug": "method/api-product-strategy",
              "icon": "strategy-outline",
              "title": "Integration Capability Strategy",
              "description": "Frame the reusable integration capability, business need, ownership, and expected reuse before selecting the implementation style.",
              "whyItMatters": "Integration and API work often jumps too quickly to a technical pattern. This station keeps the team focused on the business journey, domain meaning, value, reuse potential, ownership, and viability before selecting APIs, events, files, streams, data products, or direct integration.",
              "applyInWork": "Use shared journey, domain, value proposition, and business model canvases to gather technology-agnostic requirements and decide whether the capability should be reusable.",
              "outcomes": [
                "A technology-agnostic capability opportunity statement",
                "Shared understanding of consumers, producers, domain concepts, and reuse potential",
                "A capability value proposition and business model before architecture selection"
              ],
              "steps": [
                {
                  "text": "Map the customer or partner journey that creates the capability need and reveals tasks, pains, gains, inputs, outputs, and decision points.",
                  "resourceId": "customerJourneyCanvas",
                  "resourceTitle": "Customer Journey Canvas",
                  "canvasId": "customerJourneyCanvas"
                },
                {
                  "text": "Define the core entities, attributes, relationships, ownership, and business rules that the capability must respect.",
                  "resourceId": "domainCanvas",
                  "resourceTitle": "Domain Canvas",
                  "canvasId": "domainCanvas"
                },
                {
                  "text": "Use the Capability Value Proposition Canvas to capture consumer tasks, gains, pains, and reusable capability features without naming the delivery technology too early.",
                  "resourceId": "apiValuePropositionCanvas",
                  "resourceTitle": "API Value Proposition Canvas",
                  "canvasId": "apiValuePropositionCanvas"
                },
                {
                  "text": "Use the Capability Business Model Canvas to clarify ownership, partners, channels, costs, benefits, support, and lifecycle expectations for the reusable capability.",
                  "resourceId": "apiBusinessModelCanvas",
                  "resourceTitle": "API Business Model Canvas",
                  "canvasId": "apiBusinessModelCanvas"
                }
              ],
              "questions": [
                "Map the customer or partner journey that creates the capability need and reveals tasks, pains, gains, inputs, outputs, and decision points.",
                "Define the core entities, attributes, relationships, ownership, and business rules that the capability must respect.",
                "Use the Capability Value Proposition Canvas to capture consumer tasks, gains, pains, and reusable capability features without naming the delivery technology too early.",
                "Use the Capability Business Model Canvas to clarify ownership, partners, channels, costs, benefits, support, and lifecycle expectations for the reusable capability.",
                "Use shared journey, domain, value proposition, and business model canvases to gather technology-agnostic requirements and decide whether the capability should be reusable.",
                "Integration and API work often jumps too quickly to a technical pattern. This station keeps the team focused on the business journey, domain meaning, value, reuse potential, ownership, and viability before selecting APIs, events, files, streams, data products, or direct integration."
              ],
              "criteria": [
                "metrics-feedback-available",
                "business-goals-defined",
                "market-research-done",
                "stakeholder-approval"
              ],
              "criteriaDetails": [
                {
                  "id": "metrics-feedback-available",
                  "title": "Relevant market signals, feedback, or operational insights are available to guide this capability opportunity.",
                  "description": "Relevant market signals, feedback, or operational insights are available to guide this API opportunity."
                },
                {
                  "id": "business-goals-defined",
                  "title": "Business goals are defined.",
                  "description": "Business goals are defined."
                },
                {
                  "id": "market-research-done",
                  "title": "Market research identifies capability opportunities.",
                  "description": "Market research identifies API opportunities."
                },
                {
                  "id": "stakeholder-approval",
                  "title": "Relevant stakeholders agree this capability opportunity is worth exploring and prioritizing.",
                  "description": "Relevant stakeholders agree this API opportunity is worth exploring and prioritizing."
                }
              ],
              "baseTitle": "Strategy",
              "group": "Capability Lifecycle Core Stations",
              "lifecycleStage": "strategy",
              "stakeholders": [
                {
                  "id": "integration-architect",
                  "sourceKey": "integration-architect",
                  "sourceStakeholderId": "integration-architect",
                  "title": "Integration Architect",
                  "description": "Designs integration approaches and implementation styles that connect the capability or API with other systems.",
                  "involvement": "lead",
                  "responsibilities": []
                },
                {
                  "id": "business-owner",
                  "sourceKey": "business-owner",
                  "sourceStakeholderId": "business-owner",
                  "title": "Business Owner",
                  "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
                  "involvement": "core",
                  "responsibilities": [
                    {
                      "resourceId": "customerJourneyCanvas",
                      "resourceTitle": "Customer Journey Canvas",
                      "canvasId": "customerJourneyCanvas",
                      "role": "suggested-answer-owner"
                    }
                  ]
                },
                {
                  "id": "capability-owner",
                  "sourceKey": "capability-owner",
                  "sourceStakeholderId": "capability-owner",
                  "title": "Capability Owner",
                  "description": "Owns the capability vision, value, priorities, lifecycle, and reuse across consumers.",
                  "involvement": "core",
                  "responsibilities": [
                    {
                      "resourceId": "capabilityValuePropositionCanvas",
                      "resourceTitle": "Capability Value Proposition Canvas",
                      "canvasId": "capabilityValuePropositionCanvas",
                      "role": "suggested-answer-owner"
                    },
                    {
                      "resourceId": "capabilityBusinessModelCanvas",
                      "resourceTitle": "Capability Business Model Canvas",
                      "canvasId": "capabilityBusinessModelCanvas",
                      "role": "suggested-answer-owner"
                    }
                  ]
                },
                {
                  "id": "domain-specialist",
                  "sourceKey": "domain-specialist",
                  "sourceStakeholderId": "domain-specialist",
                  "title": "Domain Expert",
                  "description": "Brings deep knowledge of the business domain, concepts, rules, and constraints the capability or interface must reflect.",
                  "involvement": "core",
                  "responsibilities": [
                    {
                      "resourceId": "domainCanvas",
                      "resourceTitle": "Domain Canvas",
                      "canvasId": "domainCanvas",
                      "role": "suggested-answer-owner"
                    }
                  ]
                },
                {
                  "id": "platform-owner",
                  "sourceKey": "platform-owner",
                  "sourceStakeholderId": "platform-owner",
                  "title": "Platform Owner",
                  "description": "Owns platform capabilities, roadmap, operational model, and service expectations.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "api-product-owner",
                  "sourceKey": "api-product-owner",
                  "sourceStakeholderId": "api-product-owner",
                  "title": "API Product Owner",
                  "description": "Drives the API opportunity, prioritization, and product-level decisions across the lifecycle.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "partner-specialist",
                  "sourceKey": "partner-specialist",
                  "sourceStakeholderId": "partner-specialist",
                  "title": "Partner or Vendor Manager",
                  "description": "Coordinates external partner, supplier, or vendor relationships that influence capability or API strategy and delivery.",
                  "involvement": "consulted",
                  "responsibilities": []
                }
              ],
              "resources": [
                {
                  "id": "customerJourneyCanvas",
                  "slug": "resources/customer-journey-canvas",
                  "title": "Customer Journey Canvas",
                  "description": "Map customer, partner, or consumer journeys to identify needs, pain points, gains, inputs, outputs, and experience expectations.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 1,
                  "outcomes": [
                    "Shared understanding of the customer, partner, or consumer journey",
                    "Needs, pain points, gains, inputs, and outputs documented",
                    "Journey evidence available for capability, requirements, and architecture decisions"
                  ],
                  "steps": [
                    "Define customer persona",
                    "Identify triggers for the journey",
                    "Describe the journey's end",
                    "Map journey steps with inputs/outputs",
                    "Identify customer pains",
                    "Summarize customer gains",
                    "Define necessary inputs and resulting outputs",
                    "Define interactions and processing expectations for each step"
                  ],
                  "canvasId": "customerJourneyCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "domainCanvas",
                  "slug": "resources/domain-canvas",
                  "title": "Domain Canvas",
                  "description": "A modeling tool to define and communicate the key entities and relationships in your domain, ensuring semantic consistency across capabilities, integrations, APIs, data products, and services.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 152,
                  "outcomes": [
                    "Shared domain model and terminology",
                    "Core entities, relationships, rules, and ownership clarified",
                    "Semantic consistency across capabilities, integrations, APIs, data products, and services"
                  ],
                  "steps": [
                    "Define core entities, their attributes, and relationships to create a shared conceptual understanding across capabilities, integrations, APIs, data products, and services."
                  ],
                  "canvasId": "domainCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "capabilityValuePropositionCanvas",
                  "slug": "resources/capability-value-proposition-canvas",
                  "title": "Capability Value Proposition Canvas",
                  "description": "A technology-agnostic canvas for mapping consumer tasks, gains, pains, and candidate reusable capabilities before selecting an implementation style.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 2.1,
                  "outcomes": [
                    "Clear reusable capability value proposition",
                    "Consumer tasks, gains, and pains captured without assuming a technology",
                    "Candidate reusable capabilities identified for architecture evaluation"
                  ],
                  "steps": [
                    "List the consumer tasks and outcomes the capability should support.",
                    "Identify gain-enabling capability features.",
                    "Identify pain-relieving capability features.",
                    "Group the features into candidate reusable capabilities."
                  ],
                  "canvasId": "capabilityValuePropositionCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "capabilityBusinessModelCanvas",
                  "slug": "resources/capability-business-model-canvas",
                  "title": "Capability Business Model Canvas",
                  "description": "A business model canvas for reusable capabilities, covering value, consumers, ownership, engagement, costs, and benefits without assuming an implementation style.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 3.1,
                  "outcomes": [
                    "Viable reusable capability operating model",
                    "Ownership, consumers, channels, partners, and support needs clarified",
                    "Costs and benefits visible before architecture commitment"
                  ],
                  "steps": [
                    "Summarize the capability value proposition.",
                    "Identify consumer segments and engagement channels.",
                    "Define key activities, resources, and partners.",
                    "Capture costs and benefits.",
                    "Clarify ownership, funding, support, and lifecycle expectations.",
                    "Validate the model with consumers, producers, and governance stakeholders."
                  ],
                  "canvasId": "capabilityBusinessModelCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                }
              ],
              "evidence": [
                "design-artifact",
                "documentation",
                "research",
                "roadmap"
              ]
            },
            {
              "index": 2,
              "id": "api-consumer-experience",
              "slug": "method/api-consumer-experience",
              "icon": "deployed-code-account-outline",
              "title": "Integration Consumer Requirements & Onboarding",
              "description": "Capture integration consumers, provider responsibilities, onboarding needs, service expectations, and operational constraints.",
              "whyItMatters": "The right architecture depends on consumer goals, onboarding expectations, service levels, data quality needs, change tolerance, observability, support, and producer constraints.",
              "applyInWork": "Use consumer experience and onboarding guidance to make expectations explicit for both consumers and producers.",
              "outcomes": [
                "Documented consumer requirements and onboarding expectations",
                "Clear producer responsibilities and support expectations",
                "Architecture-relevant constraints ready for decision making",
                "Improved adoption through consumer empathy, standards, and producer clarity"
              ],
              "steps": [
                {
                  "text": "Use the Consumer Experience Requirements Canvas to capture consumer goals, availability, freshness, volume, performance, data quality, security, onboarding, change, observability, and recovery expectations.",
                  "resourceId": "apiValuePropositionCanvas",
                  "resourceTitle": "API Value Proposition Canvas",
                  "canvasId": "apiValuePropositionCanvas"
                },
                {
                  "text": "Use onboarding guidance to describe how consumers will find, request, test, get approved for, and start using the capability.",
                  "resourceId": "customerJourneyCanvas",
                  "resourceTitle": "Customer Journey Canvas",
                  "canvasId": "customerJourneyCanvas"
                },
                {
                  "text": "Use the resulting journey and requirements to improve onboarding, documentation, support, and feedback loops for capability consumers.",
                  "resourceId": "api-onboarding-best-practices",
                  "resourceTitle": "API Onboarding Best Practices",
                  "canvasId": null
                }
              ],
              "questions": [
                "Use the Consumer Experience Requirements Canvas to capture consumer goals, availability, freshness, volume, performance, data quality, security, onboarding, change, observability, and recovery expectations.",
                "Use onboarding guidance to describe how consumers will find, request, test, get approved for, and start using the capability.",
                "Use the resulting journey and requirements to improve onboarding, documentation, support, and feedback loops for capability consumers.",
                "Use consumer experience and onboarding guidance to make expectations explicit for both consumers and producers.",
                "The right architecture depends on consumer goals, onboarding expectations, service levels, data quality needs, change tolerance, observability, support, and producer constraints."
              ],
              "criteria": [
                "api-opportunity-documented",
                "api-reusability",
                "hide-backend-discrepancies",
                "value-prop-validated",
                "consumer-segments-identified",
                "api-roadmap-defined"
              ],
              "criteriaDetails": [
                {
                  "id": "api-opportunity-documented",
                  "title": "Capability opportunity is identified and documented.",
                  "description": "Individual API opportunities are identified and documented."
                },
                {
                  "id": "api-reusability",
                  "title": "The capability addresses a clear business need and is reusable by its intended consumers.",
                  "description": "The API meets a clear business need and is reusable for multiple API consumers."
                },
                {
                  "id": "hide-backend-discrepancies",
                  "title": "The selected interface provides an appropriate abstraction for consumers.",
                  "description": "The API is intended to shield consumers from backend complexity and inconsistencies."
                },
                {
                  "id": "value-prop-validated",
                  "title": "The capability value proposition has been validated with business and consumer stakeholders.",
                  "description": "The API value proposition has been reviewed and validated with the relevant business and consumer stakeholders."
                },
                {
                  "id": "consumer-segments-identified",
                  "title": "Consumer segments are identified.",
                  "description": "API consumer segments (internal and external) are identified."
                },
                {
                  "id": "api-roadmap-defined",
                  "title": "A high-level implementation roadmap is defined.",
                  "description": "High-level roadmaps for API development are established."
                }
              ],
              "baseTitle": "Consumer Requirements & Onboarding",
              "group": "Capability Lifecycle Core Stations",
              "lifecycleStage": "strategy",
              "stakeholders": [
                {
                  "id": "api-consumer-specialist",
                  "sourceKey": "api-consumer-specialist",
                  "sourceStakeholderId": "api-consumer-specialist",
                  "title": "API Consumer Representative",
                  "description": "Represents the needs of developers, integrators, or other API consumers who use the API directly.",
                  "involvement": "lead",
                  "responsibilities": [
                    {
                      "resourceId": "consumerExperienceRequirementsCanvas",
                      "resourceTitle": "Consumer Experience Requirements Canvas",
                      "canvasId": "consumerExperienceRequirementsCanvas",
                      "role": "suggested-answer-owner"
                    }
                  ]
                },
                {
                  "id": "customer-specialist",
                  "sourceKey": "customer-specialist",
                  "sourceStakeholderId": "customer-specialist",
                  "title": "Customer or Partner Representative",
                  "description": "Contributes the business customer or partner perspective for the journey, value, and collaboration model.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "domain-specialist",
                  "sourceKey": "domain-specialist",
                  "sourceStakeholderId": "domain-specialist",
                  "title": "Domain Expert",
                  "description": "Brings deep knowledge of the business domain, concepts, rules, and constraints the capability or interface must reflect.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "integration-architect",
                  "sourceKey": "integration-architect",
                  "sourceStakeholderId": "integration-architect",
                  "title": "Integration Architect",
                  "description": "Designs integration approaches and implementation styles that connect the capability or API with other systems.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "api-devrel-specialist",
                  "sourceKey": "api-devrel-specialist",
                  "sourceStakeholderId": "api-devrel-specialist",
                  "title": "Documentation and DevRel Owner",
                  "description": "Owns onboarding content, developer communication, and documentation quality for API consumers.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "partner-specialist",
                  "sourceKey": "partner-specialist",
                  "sourceStakeholderId": "partner-specialist",
                  "title": "Partner or Vendor Manager",
                  "description": "Coordinates external partner, supplier, or vendor relationships that influence capability or API strategy and delivery.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "operations-specialist",
                  "sourceKey": "operations-specialist",
                  "sourceStakeholderId": "operations-specialist",
                  "title": "Support and Operations Owner",
                  "description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
                  "involvement": "consulted",
                  "responsibilities": []
                }
              ],
              "resources": [
                {
                  "id": "consumerExperienceRequirementsCanvas",
                  "slug": "resources/consumer-experience-requirements-canvas",
                  "title": "Consumer Experience Requirements Canvas",
                  "description": "A requirements canvas for consumer experience and non-functional needs that should guide the later architecture and implementation-style decision.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 3.2,
                  "outcomes": [
                    "Technology-agnostic consumer and service requirements",
                    "Experience and non-functional needs captured before design starts",
                    "Architecture implications documented for implementation-style selection"
                  ],
                  "steps": [
                    "Capture consumer goals and usage context.",
                    "Document availability, timeliness, volume, performance, data quality, and consistency expectations.",
                    "Document security, privacy, onboarding, change, observability, support, and recovery expectations.",
                    "Summarize what the requirements imply for possible implementation styles."
                  ],
                  "canvasId": "consumerExperienceRequirementsCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "api-onboarding-best-practices",
                  "slug": "resources/api-onboarding-best-practices",
                  "title": "API Onboarding Best Practices",
                  "description": "Best practices to streamline API consumer onboarding journeys with step-by-step registration, discovery, and first-call guidance.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 121,
                  "outcomes": [
                    "Shared understanding of the purpose and use of API Onboarding Best Practices",
                    "A consistent approach to applying API Onboarding Best Practices",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Define the API consumer journey from discovery to troubleshooting, identifying key touchpoints and pain points.",
                    "Develop onboarding processes and resources to help API consumers understand how to use APIs effectively.",
                    "Document how consumers find and use the API, including onboarding processes and registration."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                }
              ],
              "evidence": [
                "design-artifact",
                "documentation",
                "consumer-feedback"
              ]
            },
            {
              "index": 3,
              "id": "api-platform-architecture",
              "slug": "method/api-platform-architecture",
              "icon": "code-blocks-outline",
              "title": "Integration Architecture & Platform Decisions",
              "description": "Select the integration architecture, implementation style, and platform capabilities, taking account of constraints and the governance model.",
              "whyItMatters": "Architecture choices should follow from evidence about business impact, locations, trust boundaries, capacity, latency, data ownership, consistency, operability, security, privacy, governance, and cost.",
              "applyInWork": "Compare viable architecture styles against the gathered requirements and document the selected pattern and rationale.",
              "outcomes": [
                "A justified architecture choice",
                "Documented risks, locations, capacity, security, privacy, and operability constraints",
                "Clear rationale for API, event, file, stream, data product, direct integration, or hybrid implementation style"
              ],
              "steps": [
                {
                  "text": "Use the Business Impact Canvas to identify availability, security, and data risks that influence architecture options.",
                  "resourceId": "businessImpactCanvas",
                  "resourceTitle": "Business Impact Canvas",
                  "canvasId": "businessImpactCanvas"
                },
                {
                  "text": "Use the Locations Canvas to capture geopolitical, regulatory, network, residency, and trust-boundary constraints.",
                  "resourceId": "locationsCanvas",
                  "resourceTitle": "Location Canvas",
                  "canvasId": "locationsCanvas"
                },
                {
                  "text": "Use the Capacity Canvas to capture current and future volumes, peaks, latency, caching, rate limiting, and scaling expectations.",
                  "resourceId": "capacityCanvas",
                  "resourceTitle": "Capacity Canvas",
                  "canvasId": "capacityCanvas"
                },
                {
                  "text": "Use metrics and analytics guidance to define how the chosen capability will be monitored and improved.",
                  "resourceId": "api-metrics-and-analytics",
                  "resourceTitle": "API Metrics And Analytics",
                  "canvasId": null
                }
              ],
              "questions": [
                "Use the Business Impact Canvas to identify availability, security, and data risks that influence architecture options.",
                "Use the Locations Canvas to capture geopolitical, regulatory, network, residency, and trust-boundary constraints.",
                "Use the Capacity Canvas to capture current and future volumes, peaks, latency, caching, rate limiting, and scaling expectations.",
                "Use metrics and analytics guidance to define how the chosen capability will be monitored and improved.",
                "Compare viable architecture styles against the gathered requirements and document the selected pattern and rationale.",
                "Architecture choices should follow from evidence about business impact, locations, trust boundaries, capacity, latency, data ownership, consistency, operability, security, privacy, governance, and cost."
              ],
              "criteria": [
                "api-reusability",
                "hide-backend-discrepancies",
                "value-prop-validated",
                "consumer-segments-identified",
                "api-roadmap-defined"
              ],
              "criteriaDetails": [
                {
                  "id": "api-reusability",
                  "title": "The capability addresses a clear business need and is reusable by its intended consumers.",
                  "description": "The API meets a clear business need and is reusable for multiple API consumers."
                },
                {
                  "id": "hide-backend-discrepancies",
                  "title": "The selected interface provides an appropriate abstraction for consumers.",
                  "description": "The API is intended to shield consumers from backend complexity and inconsistencies."
                },
                {
                  "id": "value-prop-validated",
                  "title": "The capability value proposition has been validated with business and consumer stakeholders.",
                  "description": "The API value proposition has been reviewed and validated with the relevant business and consumer stakeholders."
                },
                {
                  "id": "consumer-segments-identified",
                  "title": "Consumer segments are identified.",
                  "description": "API consumer segments (internal and external) are identified."
                },
                {
                  "id": "api-roadmap-defined",
                  "title": "A high-level implementation roadmap is defined.",
                  "description": "High-level roadmaps for API development are established."
                }
              ],
              "baseTitle": "Architecture & Platform Decisions",
              "group": "Capability Lifecycle Core Stations",
              "lifecycleStage": "architecture",
              "stakeholders": [
                {
                  "id": "platform-architect",
                  "sourceKey": "platform-architect",
                  "sourceStakeholderId": "platform-architect",
                  "title": "Platform Architect",
                  "description": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
                  "involvement": "lead",
                  "responsibilities": [
                    {
                      "resourceId": "locationsCanvas",
                      "resourceTitle": "Location Canvas",
                      "canvasId": "locationsCanvas",
                      "role": "suggested-answer-owner"
                    }
                  ]
                },
                {
                  "id": "compliance-specialist",
                  "sourceKey": "compliance-specialist",
                  "sourceStakeholderId": "compliance-specialist",
                  "title": "Compliance and Legal Specialist",
                  "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "integration-architect",
                  "sourceKey": "integration-architect",
                  "sourceStakeholderId": "integration-architect",
                  "title": "Integration Architect",
                  "description": "Designs integration approaches and implementation styles that connect the capability or API with other systems.",
                  "involvement": "core",
                  "responsibilities": [
                    {
                      "resourceId": "businessImpactCanvas",
                      "resourceTitle": "Business Impact Canvas",
                      "canvasId": "businessImpactCanvas",
                      "role": "suggested-answer-owner"
                    }
                  ]
                },
                {
                  "id": "platform-owner",
                  "sourceKey": "platform-owner",
                  "sourceStakeholderId": "platform-owner",
                  "title": "Platform Owner",
                  "description": "Owns platform capabilities, roadmap, operational model, and service expectations.",
                  "involvement": "core",
                  "responsibilities": [
                    {
                      "resourceId": "capacityCanvas",
                      "resourceTitle": "Capacity Canvas",
                      "canvasId": "capacityCanvas",
                      "role": "suggested-answer-owner"
                    }
                  ]
                },
                {
                  "id": "security-specialist",
                  "sourceKey": "security-specialist",
                  "sourceStakeholderId": "security-specialist",
                  "title": "Security Specialist",
                  "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "operations-specialist",
                  "sourceKey": "operations-specialist",
                  "sourceStakeholderId": "operations-specialist",
                  "title": "Support and Operations Owner",
                  "description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "api-architect",
                  "sourceKey": "api-architect",
                  "sourceStakeholderId": "api-architect",
                  "title": "API Architect",
                  "description": "Owns API architecture, design principles, and interface contract quality.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "business-owner",
                  "sourceKey": "business-owner",
                  "sourceStakeholderId": "business-owner",
                  "title": "Business Owner",
                  "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "api-engineer",
                  "sourceKey": "api-engineer",
                  "sourceStakeholderId": "api-engineer",
                  "title": "Delivery Engineer",
                  "description": "Owns implementation, automation, testing, and release flow concerns needed to deliver the capability, API, or automation reliably.",
                  "involvement": "consulted",
                  "responsibilities": []
                }
              ],
              "resources": [
                {
                  "id": "businessImpactCanvas",
                  "slug": "resources/business-impact-canvas",
                  "title": "Business Impact Canvas",
                  "description": "Identify business, availability, security, data, compliance, and operational risks that should shape architecture and platform decisions.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 4,
                  "outcomes": [
                    "Documented business and operational impact assessment",
                    "Prioritized risks and mitigation actions",
                    "Evidence for architecture and platform decisions"
                  ],
                  "steps": [
                    "Availability Risks: Identify risks and impacts.",
                    "Ways to Mitigate Availability Risks: Define mitigation measures.",
                    "Security Risks: Document security-related risks.",
                    "Ways to Mitigate Security Risks: Propose strategies to mitigate security risks.",
                    "Data Risks: Identify risks to data accuracy or availability.",
                    "Ways to Mitigate Data Risks: Plan strategies to address data risks."
                  ],
                  "canvasId": "businessImpactCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "locationsCanvas",
                  "slug": "resources/location-canvas",
                  "title": "Location Canvas",
                  "description": "Map consumer, producer, system, data, network, regulatory, and trust-boundary locations to ensure compliance and performance across regions.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 6,
                  "outcomes": [
                    "Documented location, residency, network, and regulatory requirements",
                    "Regional performance and accessibility constraints identified",
                    "Data residency, trust boundaries, and applicable regulations clarified"
                  ],
                  "steps": [
                    "Map locations of producers, source systems, platforms, and consumers.",
                    "Document where consumers are located.",
                    "Identify applicable regulations.",
                    "Document where data must reside.",
                    "Ensure the capability is accessible in all intended network regions.",
                    "Validate network performance across regions."
                  ],
                  "canvasId": "locationsCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "capacityCanvas",
                  "slug": "resources/capacity-canvas",
                  "title": "Capacity Canvas",
                  "description": "Plan capacity for current and future demand, including volumes, peaks, latency, availability, scaling, caching, and rate limits for the selected capability and implementation style.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 7,
                  "outcomes": [
                    "Capacity requirements aligned with expected business demand",
                    "Peak-load, availability, and growth assumptions documented",
                    "Scaling, caching, and rate-limiting decisions defined"
                  ],
                  "steps": [
                    "Document current business volumes",
                    "Forecast future consumption trends",
                    "Plan for peak load and availability requirements",
                    "Define caching and rate-limiting strategies",
                    "Propose scaling strategies"
                  ],
                  "canvasId": "capacityCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "partner-integration-guidelines",
                  "slug": "resources/partner-integration-guidelines",
                  "title": "Partner Integration Guidelines",
                  "description": "Integration checklists and communication patterns to manage technical and legal aspects of third-party API relationships.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 164,
                  "outcomes": [
                    "Shared understanding of the purpose and use of Partner Integration Guidelines",
                    "A consistent approach to applying Partner Integration Guidelines",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Establish integration processes and guidelines for collaborating with partners, including technical integration, data sharing, and support.",
                    "Monitor partner API performance and compliance to ensure reliability and alignment with your API strategy."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                }
              ],
              "evidence": [
                "architecture-decision",
                "documentation",
                "platform-config",
                "metrics"
              ]
            },
            {
              "index": 4,
              "id": "api-design",
              "slug": "method/api-design",
              "icon": "api",
              "title": "Integration Solution Design",
              "description": "Design the interface contract, schemas, payloads, and interaction patterns for the selected integration style.",
              "whyItMatters": "Once the architecture pattern is known, the design must turn capability requirements into clear interface contracts, interactions, schemas, data rules, lifecycle expectations, and consumer obligations.",
              "applyInWork": "Select the design resources that fit the chosen implementation style and document the interface contract before implementation.",
              "outcomes": [
                "A validated interface contract for the selected implementation style",
                "Consistent interaction, data, event, file, workflow, or API contract decisions",
                "Design traceability back to capability and consumer requirements",
                "Designs aligned with domain models and interaction patterns"
              ],
              "steps": [
                {
                  "text": "Reuse the Domain Canvas to confirm business objects, terms, rules, and ownership before contract design.",
                  "resourceId": "domainCanvas",
                  "resourceTitle": "Domain Canvas",
                  "canvasId": "domainCanvas"
                },
                {
                  "text": "Use the Interaction Canvas to describe how consumers, systems, or users interact with the capability.",
                  "resourceId": "interactionCanvas",
                  "resourceTitle": "Interaction Canvas",
                  "canvasId": "interactionCanvas"
                },
                {
                  "text": "Use REST design resources when the selected interface is a REST API.",
                  "resourceId": "restCanvas",
                  "resourceTitle": "REST Canvas",
                  "canvasId": "restCanvas"
                },
                {
                  "text": "Use Event Canvas resources when the selected interface is event-driven.",
                  "resourceId": "eventCanvas",
                  "resourceTitle": "Event Canvas",
                  "canvasId": "eventCanvas"
                },
                {
                  "text": "Use GraphQL design resources when the selected interface is GraphQL.",
                  "resourceId": "graphqlCanvas",
                  "resourceTitle": "GraphQL Canvas",
                  "canvasId": "graphqlCanvas"
                },
                {
                  "text": "Use the design principles and style guidance to align design decisions with shared rules and enable consistent audit validation.",
                  "resourceId": "api-design-principles",
                  "resourceTitle": "API Design Principles",
                  "canvasId": null
                },
                {
                  "text": "Apply contract-first or design-first approaches to capture and validate the interface contract before implementation.",
                  "resourceId": "contract-first-design",
                  "resourceTitle": "Contract First Design",
                  "canvasId": null
                },
                {
                  "text": "Use the audit checklist to ensure the design meets functional and non-functional requirements, including security, performance, and compliance.",
                  "resourceId": "api-audit-checklist",
                  "resourceTitle": "API Audit Checklist",
                  "canvasId": null
                }
              ],
              "questions": [
                "Reuse the Domain Canvas to confirm business objects, terms, rules, and ownership before contract design.",
                "Use the Interaction Canvas to describe how consumers, systems, or users interact with the capability.",
                "Use REST design resources when the selected interface is a REST API.",
                "Use Event Canvas resources when the selected interface is event-driven.",
                "Use GraphQL design resources when the selected interface is GraphQL.",
                "Use the design principles and style guidance to align design decisions with shared rules and enable consistent audit validation.",
                "Apply contract-first or design-first approaches to capture and validate the interface contract before implementation.",
                "Use the audit checklist to ensure the design meets functional and non-functional requirements, including security, performance, and compliance.",
                "Select the design resources that fit the chosen implementation style and document the interface contract before implementation.",
                "Once the architecture pattern is known, the design must turn capability requirements into clear interface contracts, interactions, schemas, data rules, lifecycle expectations, and consumer obligations."
              ],
              "criteria": [
                "architecture-patterns-validated",
                "hide-backend-discrepancies",
                "design-reflects-business-value",
                "api-consistency"
              ],
              "criteriaDetails": [
                {
                  "id": "architecture-patterns-validated",
                  "title": "The chosen architecture, platform, and implementation style have been validated with the relevant architecture, security, and platform stakeholders.",
                  "description": "The chosen API architecture and platform patterns have been validated with the relevant architecture, security, and platform stakeholders."
                },
                {
                  "id": "hide-backend-discrepancies",
                  "title": "The selected interface provides an appropriate abstraction for consumers.",
                  "description": "The API is intended to shield consumers from backend complexity and inconsistencies."
                },
                {
                  "id": "design-reflects-business-value",
                  "title": "The interface design and exposed capabilities trace back to business value and consumer needs.",
                  "description": "The API design and exposed capabilities clearly trace back to business value and user needs."
                },
                {
                  "id": "api-consistency",
                  "title": "The interface design follows agreed design standards and conventions.",
                  "description": "The API design follows our shared API product and design conventions."
                }
              ],
              "baseTitle": "Solution & Interface Design",
              "group": "Capability Lifecycle Core Stations",
              "lifecycleStage": "design",
              "stakeholders": [
                {
                  "id": "integration-architect",
                  "sourceKey": "integration-architect",
                  "sourceStakeholderId": "integration-architect",
                  "title": "Integration Architect",
                  "description": "Designs integration approaches and implementation styles that connect the capability or API with other systems.",
                  "involvement": "lead",
                  "responsibilities": []
                },
                {
                  "id": "api-consumer-specialist",
                  "sourceKey": "api-consumer-specialist",
                  "sourceStakeholderId": "api-consumer-specialist",
                  "title": "API Consumer Representative",
                  "description": "Represents the needs of developers, integrators, or other API consumers who use the API directly.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "api-designer",
                  "sourceKey": "api-designer",
                  "sourceStakeholderId": "api-designer",
                  "title": "API Designer",
                  "description": "Shapes the interface contract, interaction model, consistency, and usability of the exposed capabilities.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "domain-specialist",
                  "sourceKey": "domain-specialist",
                  "sourceStakeholderId": "domain-specialist",
                  "title": "Domain Expert",
                  "description": "Brings deep knowledge of the business domain, concepts, rules, and constraints the capability or interface must reflect.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "platform-architect",
                  "sourceKey": "platform-architect",
                  "sourceStakeholderId": "platform-architect",
                  "title": "Platform Architect",
                  "description": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "compliance-specialist",
                  "sourceKey": "compliance-specialist",
                  "sourceStakeholderId": "compliance-specialist",
                  "title": "Compliance and Legal Specialist",
                  "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "api-engineer",
                  "sourceKey": "api-engineer",
                  "sourceStakeholderId": "api-engineer",
                  "title": "Delivery Engineer",
                  "description": "Owns implementation, automation, testing, and release flow concerns needed to deliver the capability, API, or automation reliably.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "security-specialist",
                  "sourceKey": "security-specialist",
                  "sourceStakeholderId": "security-specialist",
                  "title": "Security Specialist",
                  "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
                  "involvement": "consulted",
                  "responsibilities": []
                }
              ],
              "resources": [
                {
                  "id": "domainCanvas",
                  "slug": "resources/domain-canvas",
                  "title": "Domain Canvas",
                  "description": "A modeling tool to define and communicate the key entities and relationships in your domain, ensuring semantic consistency across capabilities, integrations, APIs, data products, and services.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 152,
                  "outcomes": [
                    "Shared domain model and terminology",
                    "Core entities, relationships, rules, and ownership clarified",
                    "Semantic consistency across capabilities, integrations, APIs, data products, and services"
                  ],
                  "steps": [
                    "Define core entities, their attributes, and relationships to create a shared conceptual understanding across capabilities, integrations, APIs, data products, and services."
                  ],
                  "canvasId": "domainCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "interactionCanvas",
                  "slug": "resources/interaction-canvas",
                  "title": "Interaction Canvas",
                  "description": "Define interactions, workflows, inputs, outputs, commands, queries, events, and expected responses to ensure a consistent consumer experience.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 9,
                  "outcomes": [
                    "Defined interaction model for the selected capability",
                    "Inputs, outputs, commands, queries, events, and responses clarified",
                    "Validation rules and interaction expectations agreed"
                  ],
                  "steps": [
                    "Map interactions to user, consumer, or system tasks",
                    "Define access points, operations, commands, queries, or events for each interaction",
                    "Document inputs and outputs for each interaction.",
                    "Specify validation rules and constraints",
                    "Create interaction models for CRUD, query-driven, command-driven, and event-driven interactions"
                  ],
                  "canvasId": "interactionCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "integration-style-selection-guide",
                  "slug": "resources/integration-style-selection-guide",
                  "title": "Integration Style Selection Guide",
                  "description": "Guidance for choosing between API, event, file, stream, data product, direct integration, or hybrid implementation styles based on requirements and constraints.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 180,
                  "outcomes": [
                    "Justified integration implementation style",
                    "Tradeoffs documented across integration style options",
                    "Selected style traceable to consumer, platform, data, and operational requirements"
                  ],
                  "steps": [
                    "Compare viable integration styles against latency, volume, coupling, data ownership, freshness, governance, and operability needs.",
                    "Identify when API, event, file, stream, data product, direct integration, or hybrid approaches fit the use case.",
                    "Document constraints, risks, and platform dependencies for the selected implementation style.",
                    "Record why rejected alternatives were not selected."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                },
                {
                  "id": "restCanvas",
                  "slug": "resources/rest-canvas",
                  "title": "REST Canvas",
                  "description": "Design APIs using RESTful principles, defining resources, verbs, and example requests and responses.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 10,
                  "outcomes": [
                    "Consistent RESTful API design",
                    "Defined resources and their interactions",
                    "Example requests and responses for clarity"
                  ],
                  "steps": [
                    "Identify key resources exposed by the API",
                    "Define the structure of the API resource model",
                    "Specify HTTP verbs used to interact with resources",
                    "Provide example requests and responses for each verb"
                  ],
                  "canvasId": "restCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "eventCanvas",
                  "slug": "resources/event-canvas",
                  "title": "Event Canvas",
                  "description": "Design event-driven interfaces and integrations by defining events, triggers, schemas, producers, consumers, and processing logic.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 12,
                  "outcomes": [
                    "Defined event-driven interaction model",
                    "Events, triggers, schemas, producers, and consumers clarified",
                    "Processing, acknowledgement, and failure expectations documented"
                  ],
                  "steps": [
                    "Identify key events in the system",
                    "Define triggers for each event",
                    "Describe event processing, state changes, and failure handling.",
                    "Specify resulting outputs or acknowledgments"
                  ],
                  "canvasId": "eventCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "graphqlCanvas",
                  "slug": "resources/graphql-canvas",
                  "title": "GraphQL Canvas",
                  "description": "Design GraphQL APIs by defining types, queries, mutations, and subscriptions.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 11,
                  "outcomes": [
                    "Structured GraphQL API design",
                    "Defined types and their relationships",
                    "Clear queries, mutations, and subscriptions"
                  ],
                  "steps": [
                    "What problems are API consumers trying to solve? What data do they need?",
                    "Define GraphQL types and their attributes: What are the core types exposed (e.g., User, Order, Product)?",
                    "Map relationships between types: How do types relate to each other in nested queries?",
                    "Specify queries for data retrieval",
                    "Define mutations for data modification: What operations will modify data (e.g., create, update, delete)?",
                    "Outline subscriptions for real-time updates",
                    "Define authentication and authorization: Who can access which fields or types?",
                    "Consider if there are any pagination, filtering, or rate-limiting constraints"
                  ],
                  "canvasId": "graphqlCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                },
                {
                  "id": "contract-first-design",
                  "slug": "resources/contract-first-design",
                  "title": "Contract First Design",
                  "description": "A guideline advocating for API-first approaches using formal contracts (e.g., OpenAPI) to align stakeholders before development.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 146,
                  "outcomes": [
                    "Shared understanding of the purpose and use of Contract First Design",
                    "A consistent approach to applying Contract First Design",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Apply contract-first or design-first approaches to ensure API interface contracts are validated before implementation.",
                    "Define API interface contracts that outline the expectations, responsibilities, and usage guidelines for each API.",
                    "Use standardized formats (e.g., OpenAPI, AsyncAPI) to create machine-readable API interface contracts that are easy to share and validate."
                  ],
                  "canvasId": null,
                  "sourcePath": "src/snippets/api-contract-example.yaml",
                  "sourceUrl": null,
                  "contentMarkdown": "openapi: 3.0.3\r\ninfo:\r\n  title: Sample Catalog API\r\n  version: 1.0.0\r\n  description: |\r\n    Starter example for a read-only APIOps Cycles API.\r\n    This example keeps the contract audit-friendly and easy to extend.\r\nservers:\r\n  - url: /v1\r\n    description: Versioned API base path\r\ntags:\r\n  - name: catalog\r\n    description: Browse and search catalog items\r\npaths:\r\n  /items:\r\n    get:\r\n      tags: [catalog]\r\n      summary: List catalog items\r\n      description: Returns a paginated list of public catalog items.\r\n      operationId: listItems\r\n      parameters:\r\n        - $ref: \"#/components/parameters/searchTerm\"\r\n        - $ref: \"#/components/parameters/categoryId\"\r\n        - $ref: \"#/components/parameters/page\"\r\n        - $ref: \"#/components/parameters/pageSize\"\r\n      responses:\r\n        \"200\":\r\n          description: Item list\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemListResponse\"\r\n              examples:\r\n                default:\r\n                  value:\r\n                    data:\r\n                      - itemId: item-123\r\n                        slug: blue-widget\r\n                        name: Blue Widget\r\n                        status: published\r\n                    page:\r\n                      number: 1\r\n                      size: 20\r\n                      totalItems: 1\r\n        \"400\":\r\n          $ref: \"#/components/responses/BadRequest\"\r\n        \"429\":\r\n          $ref: \"#/components/responses/TooManyRequests\"\r\n  /items/{itemId}:\r\n    get:\r\n      tags: [catalog]\r\n      summary: Get item by id\r\n      description: Returns a single public catalog item by opaque identifier.\r\n      operationId: getItemById\r\n      parameters:\r\n        - $ref: \"#/components/parameters/itemId\"\r\n      responses:\r\n        \"200\":\r\n          description: Item details\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemDetail\"\r\n        \"400\":\r\n          $ref: \"#/components/responses/BadRequest\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\n  /items/by-slug/{slug}:\r\n    get:\r\n      tags: [catalog]\r\n      summary: Get item by slug\r\n      description: Returns a single item by public slug.\r\n      operationId: getItemBySlug\r\n      parameters:\r\n        - $ref: \"#/components/parameters/slug\"\r\n      responses:\r\n        \"200\":\r\n          description: Item details\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemDetail\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\n  /categories/{categoryId}/items:\r\n    get:\r\n      tags: [catalog]\r\n      summary: List items in category\r\n      description: Returns public items in a category.\r\n      operationId: listItemsByCategory\r\n      parameters:\r\n        - $ref: \"#/components/parameters/categoryId\"\r\n      responses:\r\n        \"200\":\r\n          description: Category item list\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemListResponse\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\ncomponents:\r\n  parameters:\r\n    itemId:\r\n      name: itemId\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9][a-z0-9-]{1,63}$\"\r\n      example: item-123\r\n    slug:\r\n      name: slug\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9]+(?:-[a-z0-9]+)*$\"\r\n      example: blue-widget\r\n    categoryId:\r\n      name: categoryId\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9][a-z0-9-]{1,63}$\"\r\n      example: home-goods\r\n    searchTerm:\r\n      name: searchTerm\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: string\r\n        minLength: 1\r\n      example: widget\r\n    page:\r\n      name: page\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: integer\r\n        minimum: 1\r\n        default: 1\r\n    pageSize:\r\n      name: pageSize\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: integer\r\n        minimum: 1\r\n        maximum: 100\r\n        default: 20\r\n  responses:\r\n    BadRequest:\r\n      description: Validation failed\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n          examples:\r\n            default:\r\n              value:\r\n                code: BAD_REQUEST\r\n                message: Invalid request\r\n    NotFound:\r\n      description: Resource not found\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n    TooManyRequests:\r\n      description: Rate limit exceeded\r\n      headers:\r\n        Retry-After:\r\n          schema:\r\n            type: integer\r\n          description: Seconds until the next allowed request.\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n  schemas:\r\n    ItemListResponse:\r\n      type: object\r\n      required: [data, page]\r\n      properties:\r\n        data:\r\n          type: array\r\n          items:\r\n            $ref: \"#/components/schemas/ItemSummary\"\r\n        page:\r\n          $ref: \"#/components/schemas/Page\"\r\n    ItemSummary:\r\n      type: object\r\n      required: [itemId, slug, name, status]\r\n      properties:\r\n        itemId:\r\n          type: string\r\n        slug:\r\n          type: string\r\n        name:\r\n          type: string\r\n        status:\r\n          type: string\r\n          enum: [published, hidden]\r\n    ItemDetail:\r\n      allOf:\r\n        - $ref: \"#/components/schemas/ItemSummary\"\r\n        - type: object\r\n          properties:\r\n            description:\r\n              type: string\r\n            categories:\r\n              type: array\r\n              items:\r\n                type: string\r\n            variants:\r\n              type: array\r\n              items:\r\n                $ref: \"#/components/schemas/Variant\"\r\n    Variant:\r\n      type: object\r\n      required: [variantId, sku, price, inventory]\r\n      properties:\r\n        variantId:\r\n          type: string\r\n        sku:\r\n          type: string\r\n        price:\r\n          $ref: \"#/components/schemas/Price\"\r\n        inventory:\r\n          $ref: \"#/components/schemas/Inventory\"\r\n    Price:\r\n      type: object\r\n      required: [amount, currency]\r\n      properties:\r\n        amount:\r\n          type: number\r\n          format: decimal\r\n        currency:\r\n          type: string\r\n          example: EUR\r\n    Inventory:\r\n      type: object\r\n      required: [available]\r\n      properties:\r\n        available:\r\n          type: integer\r\n          minimum: 0\r\n        reserved:\r\n          type: integer\r\n          minimum: 0\r\n        source:\r\n          type: string\r\n    Page:\r\n      type: object\r\n      required: [number, size, totalItems]\r\n      properties:\r\n        number:\r\n          type: integer\r\n        size:\r\n          type: integer\r\n        totalItems:\r\n          type: integer\r\n    ErrorResponse:\r\n      type: object\r\n      required: [code, message]\r\n      properties:\r\n        code:\r\n          type: string\r\n        message:\r\n          type: string\r\n",
                  "draft": true
                }
              ],
              "evidence": [
                "spec",
                "contract",
                "design-artifact",
                "documentation"
              ]
            },
            {
              "index": 5,
              "id": "api-delivery",
              "slug": "method/api-delivery",
              "icon": "code",
              "title": "Integration Delivery & Operations",
              "description": "Build, test, automate, deploy, and operate the integration capability using its selected implementation style and validated interface contract.",
              "whyItMatters": "A reusable capability needs reliable delivery and operations regardless of whether it becomes an API, event stream, file exchange, data product, or direct integration.",
              "applyInWork": "Apply delivery, testing, CI/CD, operations, and security guidance to the chosen implementation style.",
              "outcomes": [
                "A delivered capability aligned with the validated interface contract",
                "Automated testing, deployment, and environment controls",
                "Security, operations, and quality practices appropriate to the chosen pattern",
                "Traceable delivery and release controls"
              ],
              "steps": [
                {
                  "text": "Use development best practices to implement the validated interface contract with established frameworks, libraries, and team standards.",
                  "resourceId": "api-development-best-practices",
                  "resourceTitle": "API Development Best Practices",
                  "canvasId": null
                },
                {
                  "text": "Build the implementation from the validated interface contract using established frameworks, libraries, and team standards.",
                  "resourceId": "api-development-best-practices",
                  "resourceTitle": "API Development Best Practices",
                  "canvasId": null
                },
                {
                  "text": "Use testing guidance to verify functionality, data quality, compatibility, security, performance, resilience, and recovery expectations.",
                  "resourceId": "api-testing-best-practices",
                  "resourceTitle": "API Testing Best Practices",
                  "canvasId": null
                },
                {
                  "text": "Use CI/CD guidance to automate build, test, deployment, configuration, and traceability.",
                  "resourceId": "apiops-CI-CD-for-apis",
                  "resourceTitle": "APIOps CI/CD For APIs",
                  "canvasId": null
                },
                {
                  "text": "Use security guidance to protect data, access, credentials, and platform boundaries.",
                  "resourceId": "api-security-best-practices",
                  "resourceTitle": "API Security Best Practices",
                  "canvasId": null
                },
                {
                  "text": "Use the audit checklist to ensure the solution meets functional and non-functional requirements, including security, performance, and compliance.",
                  "resourceId": "api-audit-checklist",
                  "resourceTitle": "API Audit Checklist",
                  "canvasId": null
                }
              ],
              "questions": [
                "Use development best practices to implement the validated interface contract with established frameworks, libraries, and team standards.",
                "Build the implementation from the validated interface contract using established frameworks, libraries, and team standards.",
                "Use testing guidance to verify functionality, data quality, compatibility, security, performance, resilience, and recovery expectations.",
                "Use CI/CD guidance to automate build, test, deployment, configuration, and traceability.",
                "Use security guidance to protect data, access, credentials, and platform boundaries.",
                "Use the audit checklist to ensure the solution meets functional and non-functional requirements, including security, performance, and compliance.",
                "Apply delivery, testing, CI/CD, operations, and security guidance to the chosen implementation style.",
                "A reusable capability needs reliable delivery and operations regardless of whether it becomes an API, event stream, file exchange, data product, or direct integration."
              ],
              "criteria": [
                "architecture-patterns-validated",
                "hide-backend-discrepancies",
                "design-reflects-business-value",
                "api-consistency"
              ],
              "criteriaDetails": [
                {
                  "id": "architecture-patterns-validated",
                  "title": "The chosen architecture, platform, and implementation style have been validated with the relevant architecture, security, and platform stakeholders.",
                  "description": "The chosen API architecture and platform patterns have been validated with the relevant architecture, security, and platform stakeholders."
                },
                {
                  "id": "hide-backend-discrepancies",
                  "title": "The selected interface provides an appropriate abstraction for consumers.",
                  "description": "The API is intended to shield consumers from backend complexity and inconsistencies."
                },
                {
                  "id": "design-reflects-business-value",
                  "title": "The interface design and exposed capabilities trace back to business value and consumer needs.",
                  "description": "The API design and exposed capabilities clearly trace back to business value and user needs."
                },
                {
                  "id": "api-consistency",
                  "title": "The interface design follows agreed design standards and conventions.",
                  "description": "The API design follows our shared API product and design conventions."
                }
              ],
              "baseTitle": "Delivery & Operations",
              "group": "Capability Lifecycle Core Stations",
              "lifecycleStage": "delivery",
              "stakeholders": [
                {
                  "id": "api-engineer",
                  "sourceKey": "api-engineer",
                  "sourceStakeholderId": "api-engineer",
                  "title": "Delivery Engineer",
                  "description": "Owns implementation, automation, testing, and release flow concerns needed to deliver the capability, API, or automation reliably.",
                  "involvement": "lead",
                  "responsibilities": []
                },
                {
                  "id": "integration-architect",
                  "sourceKey": "integration-architect",
                  "sourceStakeholderId": "integration-architect",
                  "title": "Integration Architect",
                  "description": "Designs integration approaches and implementation styles that connect the capability or API with other systems.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "platform-architect",
                  "sourceKey": "platform-architect",
                  "sourceStakeholderId": "platform-architect",
                  "title": "Platform Architect",
                  "description": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "security-specialist",
                  "sourceKey": "security-specialist",
                  "sourceStakeholderId": "security-specialist",
                  "title": "Security Specialist",
                  "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "operations-specialist",
                  "sourceKey": "operations-specialist",
                  "sourceStakeholderId": "operations-specialist",
                  "title": "Support and Operations Owner",
                  "description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "api-designer",
                  "sourceKey": "api-designer",
                  "sourceStakeholderId": "api-designer",
                  "title": "API Designer",
                  "description": "Shapes the interface contract, interaction model, consistency, and usability of the exposed capabilities.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "compliance-specialist",
                  "sourceKey": "compliance-specialist",
                  "sourceStakeholderId": "compliance-specialist",
                  "title": "Compliance and Legal Specialist",
                  "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "partner-specialist",
                  "sourceKey": "partner-specialist",
                  "sourceStakeholderId": "partner-specialist",
                  "title": "Partner or Vendor Manager",
                  "description": "Coordinates external partner, supplier, or vendor relationships that influence capability or API strategy and delivery.",
                  "involvement": "consulted",
                  "responsibilities": []
                }
              ],
              "resources": [
                {
                  "id": "api-development-best-practices",
                  "slug": "resources/api-development-best-practices",
                  "title": "API Development Best Practices",
                  "description": "Implementation guidance for turning a validated API interface contract into a consistent, maintainable API codebase using standard libraries, reusable patterns, and aligned development workflows.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 112,
                  "outcomes": [
                    "Shared understanding of the purpose and use of API Development Best Practices",
                    "A consistent approach to applying API Development Best Practices",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Apply these practices to the validated API interface contract and implementation plan before coding begins.",
                    "Use established frameworks, libraries, and coding standards to implement the contract consistently and maintainably."
                  ],
                  "canvasId": null,
                  "sourcePath": "src/snippets/api-design-principles-guidance.md",
                  "sourceUrl": null,
                  "contentMarkdown": "## How to start the API Delivery work based on the previous phases (\"stations\")\r\n\r\nUse this guidance at the start of `API Delivery` after the API contract (e.g. OpenAPI) and the key outputs from earlier stations have been reviewed and accepted.\r\n\r\nThe goal is not to invent implementation in isolation. The goal is to turn the agreed outputs from earlier stations into concrete code structure, validation rules, runtime behavior, and API product delivery decisions.\r\n\r\n---\r\n\r\n### 1. Start From The Validated Contract\r\n\r\n- Treat the validated API contract as the main reference point for implementation decisions.\r\n- Keep the contract and implementation aligned throughout the API product delivery.\r\n- Use the contract to drive request validation, response mapping, documentation, and tests.\r\n\r\n---\r\n\r\n### 2. Use Domain Outputs To Preserve Business Meaning\r\n\r\n- Use the `Domain Canvas` outputs to guide naming, how the implementation is split into clear business responsibilities, and how different backend systems are connected without exposing their differences.\r\n- Preserve the validated meanings of entities, attributes, statuses, and source-of-truth rules.\r\n- Avoid leaking backend-specific models or inconsistencies into the public API.\r\n\r\n---\r\n\r\n### 3. Use Journey Outputs To Preserve Critical Flows\r\n\r\n- Use the `Customer Journey Canvas` outputs to identify which user flows are most important to support first.\r\n- Use the `API Consumer Experience` outputs to keep the API understandable, predictable, and easy to integrate.\r\n- Let the agreed journey priorities decide which implementation paths need the highest reliability, lowest latency, clearest errors, and strongest operational focus.\r\n\r\n---\r\n\r\n### 4. Use Value Proposition Outputs To Preserve Consumer Value\r\n\r\n- Use the `API Value Proposition Canvas` outputs to keep the implementation focused on the agreed pains, gains, and API features.\r\n- Preserve the field meanings, behavior, and promises that made the API valuable in the earlier stations.\r\n- Ensure error handling, freshness, and naming support both the intended developer experience and the business use case.\r\n\r\n---\r\n\r\n### 5. Use Architecture Outputs To Shape Runtime Decisions\r\n\r\n- Use the `Business Impact Canvas` outputs to guide resilience, timeout, fallback, and degradation decisions.\r\n- Use the `Locations Canvas` outputs to guide network boundaries, trust boundaries, access paths, and deployment constraints.\r\n- Use the `Capacity Canvas` outputs to guide rate limits, caching, scaling, and peak-load behavior.\r\n- Use the `API Metrics And Analytics` guidance to decide what must be observed from the first implementation onward.\r\n\r\n---\r\n\r\n### 6. Use Interaction And Protocol Design Outputs To Shape Code Structure\r\n\r\n- Use the `Interaction Canvas` outputs to avoid implementing unsupported interaction styles too early.\r\n- Use the `REST`, `Event`, or `GraphQL` design outputs to shape protocol-specific request, response, and validation behavior.\r\n- Reflect the selected interaction style clearly in code structure, responsibilities, and testing strategy.\r\n\r\n---\r\n\r\n### 7. Use Audit Outputs To Improve Delivery Before Coding Goes Too Far\r\n\r\n- Use the audit findings to remove ambiguity before implementation spreads across the codebase.\r\n- Fix unclear request rules, missing validation, weak error contracts, and operational gaps early.\r\n- Treat audit as a design-improvement loop before production, not only as a final decision gate.\r\n\r\n---\r\n\r\n### 8. Apply The Guidance, Then Summarize\r\n\r\n- Apply this guidance to the current API and implementation plan.\r\n- Summarize the implications for code structure, request validation, source integration, security, monitoring and alerts, and testing.\r\n- Do not create a separate delivery artifact unless the team or user specifically needs one.\r\n",
                  "draft": true
                },
                {
                  "id": "api-testing-best-practices",
                  "slug": "resources/api-testing-best-practices",
                  "title": "API Testing Best Practices",
                  "description": "Guidelines for implementing automated functional, performance, and security testing throughout the API lifecycle.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 133,
                  "outcomes": [
                    "Shared understanding of the purpose and use of API Testing Best Practices",
                    "A consistent approach to applying API Testing Best Practices",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Test APIs for functionality, security, and performance using automated testing tools.",
                    "Integrate functional and non-functional testing into the CI/CD pipeline to ensure APIs meet quality standards.",
                    "Use automated testing tools to validate API functionality, security, and performance."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                },
                {
                  "id": "apiops-CI-CD-for-apis",
                  "slug": "resources/apiops-CI-CD-for-apis",
                  "title": "APIOps CI/CD For APIs",
                  "description": "Deployment guidance that integrates API lifecycle tasks—design, testing, governance—into continuous integration and delivery pipelines.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 140,
                  "outcomes": [
                    "Shared understanding of the purpose and use of APIOps CI/CD For APIs",
                    "A consistent approach to applying APIOps CI/CD For APIs",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Use CI/CD pipelines to automate build, test, and deployment processes, ensuring consistent quality and traceability.",
                    "Integrate automated tests into the CI/CD pipeline to ensure continuous validation of API quality.",
                    "Implement deployment strategies (e.g., blue-green deployments, canary releases) to minimize risks during API releases.",
                    "Establish a habit of reviewing metrics and planning continuous improvement activities."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                },
                {
                  "id": "api-security-best-practices",
                  "slug": "resources/api-security-best-practices",
                  "title": "API Security Best Practices",
                  "description": "A set of actionable controls for securing APIs, including authentication, authorization, encryption, rate-limiting, and pipeline-level compliance checks.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 130,
                  "outcomes": [
                    "Shared understanding of the purpose and use of API Security Best Practices",
                    "A consistent approach to applying API Security Best Practices",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Ensure APIs meet security and compliance requirements through automated checks and audits.",
                    "Implement security measures such as authentication, authorization, encryption, and rate limiting to protect APIs from threats.",
                    "Implement automated security checks and compliance validations in the CI/CD pipeline to ensure APIs are secure and compliant."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                },
                {
                  "id": "partner-integration-guidelines",
                  "slug": "resources/partner-integration-guidelines",
                  "title": "Partner Integration Guidelines",
                  "description": "Integration checklists and communication patterns to manage technical and legal aspects of third-party API relationships.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 164,
                  "outcomes": [
                    "Shared understanding of the purpose and use of Partner Integration Guidelines",
                    "A consistent approach to applying Partner Integration Guidelines",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Establish integration processes and guidelines for collaborating with partners, including technical integration, data sharing, and support.",
                    "Monitor partner API performance and compliance to ensure reliability and alignment with your API strategy."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                }
              ],
              "evidence": [
                "implementation",
                "pipeline-config",
                "test-report",
                "security-report"
              ]
            },
            {
              "index": 6,
              "id": "api-audit",
              "slug": "method/api-audit",
              "icon": "check-box-outline",
              "title": "Integration Readiness Assurance",
              "description": "Assure integration readiness, governance, quality, security, compliance, and operational evidence before release.",
              "whyItMatters": "Reusable capabilities create operational, data, security, privacy, compliance, and consumer-impact risks. Readiness checks reduce surprises before release or production use.",
              "applyInWork": "Use audit and compliance resources to verify that the capability is ready for controlled release and reuse.",
              "outcomes": [
                "Documented readiness for release and reuse",
                "Known gaps and mitigations before release",
                "Evidence for governance, compliance, support, and operational approval",
                "Reduced risk of issues in production"
              ],
              "steps": [
                {
                  "text": "Use the audit checklist as a reusable quality checklist for interface contract, documentation, security, performance, and compliance readiness.",
                  "resourceId": "api-audit-checklist",
                  "resourceTitle": "API Audit Checklist",
                  "canvasId": null
                },
                {
                  "text": "Use checklists, linters, and testing tools to verify consistency and conformance with standards.",
                  "resourceId": "api-compliance-best-practices",
                  "resourceTitle": "API Compliance Best Practices",
                  "canvasId": null
                },
                {
                  "text": "Collaborate with governance teams and domain experts to ensure the capability is ready for production.",
                  "resourceTitle": "",
                  "canvasId": null
                }
              ],
              "questions": [
                "Use the audit checklist as a reusable quality checklist for interface contract, documentation, security, performance, and compliance readiness.",
                "Use checklists, linters, and testing tools to verify consistency and conformance with standards.",
                "Collaborate with governance teams and domain experts to ensure the capability is ready for production.",
                "Use audit and compliance resources to verify that the capability is ready for controlled release and reuse.",
                "Reusable capabilities create operational, data, security, privacy, compliance, and consumer-impact risks. Readiness checks reduce surprises before release or production use."
              ],
              "criteria": [
                "architecture-patterns-validated",
                "design-reflects-business-value",
                "api-description-available",
                "api-consistency",
                "api-contract-tested"
              ],
              "criteriaDetails": [
                {
                  "id": "architecture-patterns-validated",
                  "title": "The chosen architecture, platform, and implementation style have been validated with the relevant architecture, security, and platform stakeholders.",
                  "description": "The chosen API architecture and platform patterns have been validated with the relevant architecture, security, and platform stakeholders."
                },
                {
                  "id": "design-reflects-business-value",
                  "title": "The interface design and exposed capabilities trace back to business value and consumer needs.",
                  "description": "The API design and exposed capabilities clearly trace back to business value and user needs."
                },
                {
                  "id": "api-description-available",
                  "title": "The interface and its capabilities are documented clearly enough for review, audit, and onboarding.",
                  "description": "The API and its exposed capabilities are described clearly enough for review, audit, and onboarding."
                },
                {
                  "id": "api-consistency",
                  "title": "The interface design follows agreed design standards and conventions.",
                  "description": "The API design follows our shared API product and design conventions."
                },
                {
                  "id": "api-contract-tested",
                  "title": "The interface contract has been validated and tested against functional and non-functional requirements.",
                  "description": "The API contract is tested and meets functional and non-functional requirements."
                }
              ],
              "baseTitle": "Quality & Readiness Assurance",
              "group": "Capability Lifecycle Core Stations",
              "lifecycleStage": "publishing",
              "stakeholders": [
                {
                  "id": "governance-specialist",
                  "sourceKey": "governance-specialist",
                  "sourceStakeholderId": "governance-specialist",
                  "title": "API Governance Owner",
                  "description": "Represents review, audit, and organization-wide governance practices for API quality and conformity.",
                  "involvement": "lead",
                  "responsibilities": []
                },
                {
                  "id": "compliance-specialist",
                  "sourceKey": "compliance-specialist",
                  "sourceStakeholderId": "compliance-specialist",
                  "title": "Compliance and Legal Specialist",
                  "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "integration-architect",
                  "sourceKey": "integration-architect",
                  "sourceStakeholderId": "integration-architect",
                  "title": "Integration Architect",
                  "description": "Designs integration approaches and implementation styles that connect the capability or API with other systems.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "security-specialist",
                  "sourceKey": "security-specialist",
                  "sourceStakeholderId": "security-specialist",
                  "title": "Security Specialist",
                  "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "operations-specialist",
                  "sourceKey": "operations-specialist",
                  "sourceStakeholderId": "operations-specialist",
                  "title": "Support and Operations Owner",
                  "description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "business-owner",
                  "sourceKey": "business-owner",
                  "sourceStakeholderId": "business-owner",
                  "title": "Business Owner",
                  "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "api-engineer",
                  "sourceKey": "api-engineer",
                  "sourceStakeholderId": "api-engineer",
                  "title": "Delivery Engineer",
                  "description": "Owns implementation, automation, testing, and release flow concerns needed to deliver the capability, API, or automation reliably.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "platform-architect",
                  "sourceKey": "platform-architect",
                  "sourceStakeholderId": "platform-architect",
                  "title": "Platform Architect",
                  "description": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
                  "involvement": "consulted",
                  "responsibilities": []
                }
              ],
              "resources": [
                {
                  "id": "api-audit-checklist",
                  "slug": "resources/api-audit-checklist",
                  "title": "API Audit Checklist",
                  "description": "A lifecycle-based checklist to verify API readiness across design, delivery, publishing, and compliance using defined audit criteria and evidence.",
                  "category": "checklist",
                  "icon": "check-box-outline",
                  "order": 13,
                  "outcomes": [
                    "Shared understanding of the purpose and use of API Audit Checklist",
                    "A consistent approach to applying API Audit Checklist",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Use the API Audit Checklist to ensure the API design meets functional and non-functional requirements, including security, performance, and compliance.",
                    "Conduct audits to assess lifecycle coverage and verify that the API meets business, design, and operational standards.",
                    "Ensure that documentation, security models, gateway configuration, and legal requirements are clearly defined, validated, and supported by evidence."
                  ],
                  "canvasId": null,
                  "sourcePath": "src/snippets/api-audit-checklist.json",
                  "sourceUrl": null,
                  "contentMarkdown": "{\r\n  \"profiles\": {\r\n    \"read-only\": {\r\n      \"description\": \"API profile that is read-only and does not allow create, update, or delete operations.\"\r\n    },\r\n    \"full-crud\": {\r\n      \"description\": \"General API profile that allows create, update, and delete operations.\"\r\n    }\r\n  },\r\n  \"lifecycleStages\": [\r\n    {\r\n      \"id\": \"strategy\",\r\n      \"title\": \"Strategy\",\r\n      \"readinessLabel\": \"Strategy is Ready When...\",\r\n      \"order\": 1\r\n    },\r\n    {\r\n      \"id\": \"architecture\",\r\n      \"title\": \"Architecture\",\r\n      \"readinessLabel\": \"Architecture is Ready When...\",\r\n      \"order\": 2\r\n    },\r\n    {\r\n      \"id\": \"design\",\r\n      \"title\": \"Design\",\r\n      \"readinessLabel\": \"Design is Ready When...\",\r\n      \"order\": 3\r\n    },\r\n    {\r\n      \"id\": \"delivery\",\r\n      \"title\": \"Delivery\",\r\n      \"readinessLabel\": \"Delivery is Ready When...\",\r\n      \"order\": 4\r\n    },\r\n    {\r\n      \"id\": \"publishing\",\r\n      \"title\": \"Publishing\",\r\n      \"readinessLabel\": \"Publishing is Ready When...\",\r\n      \"order\": 5\r\n    },\r\n    {\r\n      \"id\": \"improving\",\r\n      \"title\": \"Improving\",\r\n      \"readinessLabel\": \"Improving is Ready When...\",\r\n      \"order\": 6\r\n    }\r\n  ],\r\n  \"stages\": [\r\n    {\r\n      \"id\": \"strategy\",\r\n      \"title\": \"Strategy\",\r\n      \"readinessLabel\": \"Strategy is Ready When...\",\r\n      \"order\": 1,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"based-on-clear-business-needs\",\r\n          \"label\": \"API is based on clear business needs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"strategy\",\r\n          \"producedByStation\": [\r\n            \"api-product-strategy\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"business-goals-defined\",\r\n            \"market-research-done\",\r\n            \"stakeholder-approval\",\r\n            \"metrics-feedback-available\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DOMAIN-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiBusinessModelCanvas\",\r\n            \"apiValuePropositionCanvas\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"design-artifact\",\r\n            \"documentation\",\r\n            \"research\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-product-strategy/apiValuePropositionCanvas.empty.json\",\r\n            \"specs/canvases/api-product-strategy/apiBusinessModelCanvas.empty.json\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"concept-items-audited\",\r\n          \"label\": \"All concept checklist items are audited\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"aggregate\",\r\n          \"check\": {\r\n            \"type\": \"stageCoverage\",\r\n            \"stageId\": \"strategy\"\r\n          },\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"strategy\",\r\n          \"producedByStation\": [\r\n            \"api-product-strategy\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"business-goals-defined\",\r\n            \"market-research-done\",\r\n            \"stakeholder-approval\",\r\n            \"metrics-feedback-available\",\r\n            \"api-opportunity-documented\",\r\n            \"api-reusability\",\r\n            \"value-prop-validated\",\r\n            \"consumer-segments-identified\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"report\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"audit/concept-review-report.json\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"architecture\",\r\n      \"title\": \"Architecture\",\r\n      \"readinessLabel\": \"Architecture is Ready When...\",\r\n      \"order\": 2,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"versioning-decided\",\r\n          \"label\": \"Versioning strategy decided and supported by gateway\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"architecture\",\r\n          \"producedByStation\": [\r\n            \"api-platform-architecture\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-roadmap-defined\",\r\n            \"api-reusability\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-VERSION-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"contract-first-design\",\r\n            \"api-versioning-best-practices\",\r\n            \"apiops-CI-CD-for-apis\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"ci-cd\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"docs/api/architecture/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"only-via-gateway\",\r\n          \"label\": \"Only accessible via API gateway\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"architecture\",\r\n          \"producedByStation\": [\r\n            \"api-platform-architecture\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-reusability\",\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-02\",\r\n            \"REST-CAPACITY-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"businessImpactCanvas\",\r\n            \"locationsCanvas\",\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"gateway-config\",\r\n            \"infra-config\",\r\n            \"security-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/architecture/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"rate-limits-enforced\",\r\n          \"label\": \"Rate limits are enforced\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"architecture\",\r\n          \"producedByStation\": [\r\n            \"api-platform-architecture\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-roadmap-defined\",\r\n            \"api-reusability\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CAPACITY-01\",\r\n            \"REST-OBS-01\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"capacityCanvas\",\r\n            \"api-security-best-practices\",\r\n            \"scalable-infrastructure-best-practices\",\r\n            \"api-metrics-and-analytics\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"gateway-config\",\r\n            \"runtime\",\r\n            \"monitoring\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-platform-architecture/capacityCanvas.empty.json\",\r\n            \"docs/api/architecture/README.md\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"design\",\r\n      \"title\": \"Design\",\r\n      \"readinessLabel\": \"Design is Ready When...\",\r\n      \"order\": 3,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"endpoint-descriptions-present\",\r\n          \"label\": \"Endpoints have business value and feature descriptions\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"operationDescriptions\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"value-prop-validated\",\r\n            \"api-opportunity-documented\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CX-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiValuePropositionCanvas\",\r\n            \"customerJourneyCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"design-artifact\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"specs/canvases/api-product-strategy/apiValuePropositionCanvas.empty.json\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"hides-raw-backend-data\",\r\n          \"label\": \"API hides raw backend data and is designed for shared use\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"hide-backend-discrepancies\",\r\n            \"design-reflects-business-value\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DOMAIN-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"interactionCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"design-artifact\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-product-strategy/domainCanvas.empty.json\",\r\n            \"specs/canvases/api-design/interactionCanvas.empty.json\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"design-consistent\",\r\n          \"label\": \"API design is consistent with other APIs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-platform-architecture\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"architecture-patterns-validated\",\r\n            \"api-reusability\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DOMAIN-02\",\r\n            \"REST-CX-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"documentation\",\r\n            \"design-artifact\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-design/restCanvas.empty.json\",\r\n            \"docs/api/design/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"descriptive-english-naming\",\r\n          \"label\": \"Data and attribute naming uses descriptive English\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"fieldNamesDescriptive\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-NAMING-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"mandatory-fields-specified\",\r\n          \"label\": \"Mandatory fields are specified\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"requiredFieldsPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-VALIDATION-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"contract\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"dates-use-iso\",\r\n          \"label\": \"Dates use ISO format with timezone\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"dateFormatTimezone\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DATA-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"general-data-uses-standard-values\",\r\n          \"label\": \"General data uses standard values\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"standardizedEnumsOrPatterns\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"design-reflects-business-value\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DATA-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"field-names-avoid-acronyms\",\r\n          \"label\": \"Field names avoid acronyms and use full words\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"avoidAcronyms\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-NAMING-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"create-returns-identifiers\",\r\n          \"label\": \"Creating new resources returns identifiers\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is read-only and does not create resources.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-201-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"paths-max-two-resources\",\r\n          \"label\": \"Endpoint paths contain max two resources or sub-resources\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"pathDepthMax\",\r\n            \"maxDepth\": 2\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PATH-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"examples-present\",\r\n          \"label\": \"Endpoints and attributes include examples\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"examplesPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CX-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"restCanvas\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"post-for-create-update\",\r\n          \"label\": \"POST is used for create or update\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose create or update operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"design-reflects-business-value\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-POST-01\",\r\n            \"REST-HTTP-PUT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"delete-for-remove\",\r\n          \"label\": \"DELETE is used to remove resources\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose delete operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-DELETE-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"get-no-request-body\",\r\n          \"label\": \"GET has no request body and returns content\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"getNoRequestBody\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-GET-01\",\r\n            \"REST-RESP-200-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"get-empty-returns-204\",\r\n          \"label\": \"GET returns 204 if response body is empty\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"The current contract returns content for all GET operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-204-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"post-returns-200\",\r\n          \"label\": \"POST returns 200 OK when updating\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose POST updates.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-200-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"post-returns-201\",\r\n          \"label\": \"POST returns 201 Created with ID on create\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose POST creates.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-201-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"delete-returns-204\",\r\n          \"label\": \"DELETE returns 204 on success\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose DELETE operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-204-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"400-errors-specific\",\r\n          \"label\": \"400 errors provide specific error information\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"errorResponsesSpecific\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-ERROR-400-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"restCanvas\",\r\n            \"api-audit-checklist\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"401-unauthorized\",\r\n          \"label\": \"401 Unauthorized for wrong credentials\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"The current public storefront contract is intentionally unauthenticated.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-ERROR-401-01\",\r\n            \"REST-SEC-01\",\r\n            \"REST-SEC-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"security-config\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"403-forbidden\",\r\n          \"label\": \"403 Forbidden for unauthorized operations\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"The current profile is public read-only and exposes no unauthorized operations.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-ERROR-403-01\",\r\n            \"REST-SEC-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"security-config\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"spec-contains-schemas\",\r\n          \"label\": \"Spec contains request and response schema\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"schemasPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CONTRACT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"contract-first-design\",\r\n            \"restCanvas\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"contract\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"pseudo-identifiers\",\r\n          \"label\": \"UUIDs or pseudo-identifiers instead of DB IDs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"opaqueIdentifiers\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"hide-backend-discrepancies\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-07\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"contract-first-design\",\r\n            \"api-security-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"no-sensitive-data-in-urls\",\r\n          \"label\": \"No sensitive data in URLs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"noSensitiveDataInPaths\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"hide-backend-discrepancies\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-06\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"contract-first-design\",\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"http-methods-match-resources\",\r\n          \"label\": \"HTTP methods only for intended resources\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"methodResourceConsistency\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-GET-01\",\r\n            \"REST-HTTP-POST-01\",\r\n            \"REST-HTTP-PUT-01\",\r\n            \"REST-HTTP-DELETE-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"delivery\",\r\n      \"title\": \"Delivery\",\r\n      \"readinessLabel\": \"Delivery is Ready When...\",\r\n      \"order\": 4,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"design-items-audited\",\r\n          \"label\": \"All prototype and design items are audited\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"aggregate\",\r\n          \"check\": {\r\n            \"type\": \"stageCoverage\",\r\n            \"stageId\": \"design\"\r\n          },\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"design-reflects-business-value\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"report\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"audit/production-readiness-review.json\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"spec-validated-on-change\",\r\n          \"label\": \"Spec validated on every change\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"validationWorkflowPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-audit-checklist\",\r\n            \"contract-first-design\",\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"api-testing-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"ci-cd\",\r\n            \"spec\",\r\n            \"test\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \".github/workflows/openapi-lint.yml\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"schema-and-examples-pass\",\r\n          \"label\": \"Schema and examples pass validation\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"examplesPassValidation\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"architecture-patterns-validated\",\r\n            \"api-contract-tested\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-01\",\r\n            \"REST-CONTRACT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"contract-first-design\",\r\n            \"api-audit-checklist\",\r\n            \"api-testing-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"test\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"uses-https\",\r\n          \"label\": \"Uses HTTPS or encrypted protocols\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-05\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"auth-protection\",\r\n          \"label\": \"Endpoints protected by authentication\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is intentionally public read-only.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-01\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"gateway-config\",\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"token-auth\",\r\n          \"label\": \"Token-based authentication\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is intentionally public read-only.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"csrf-protection\",\r\n          \"label\": \"Protected against CSRF\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is intentionally public read-only.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-08\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-development-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"code\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"inputs-auto-validated\",\r\n          \"label\": \"Inputs auto-validated by framework\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-VALIDATION-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-development-best-practices\",\r\n            \"contract-first-design\",\r\n            \"api-testing-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"code\",\r\n            \"test\",\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"docs/api/delivery/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"outputs-auto-escaped\",\r\n          \"label\": \"Outputs auto-escaped by framework\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"JSON APIs do not typically require output escaping in the same way as HTML rendering.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-development-best-practices\",\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"code\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"encryption-in-transit\",\r\n          \"label\": \"Encryption for data in transit and storage\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-05\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\",\r\n            \"api-metrics-and-analytics\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"infra-config\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"message-integrity\",\r\n          \"label\": \"Message integrity implemented\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-OBS-01\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"api-compliance-best-practices\",\r\n            \"api-metrics-and-analytics\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"monitoring\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/architecture/README.md\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"publishing\",\r\n      \"title\": \"Publishing\",\r\n      \"readinessLabel\": \"Publishing is Ready When...\",\r\n      \"order\": 5,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"published-via-api-management\",\r\n          \"label\": \"Published via API management\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"api-onboarding-best-practices\",\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"gateway-config\",\r\n            \"ci-cd\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \".github/workflows/openapi-lint.yml\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"visible-in-dev-portal\",\r\n          \"label\": \"Visible in developer portal\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-documentation-ready\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"api-community-engagement-strategies\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"documentation\",\r\n            \"runtime\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"docs-auto-generated\",\r\n          \"label\": \"Docs auto-generated from spec and schema\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\",\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-documentation-ready\",\r\n            \"api-ready-for-publishing\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CONTRACT-02\",\r\n            \"REST-PUBLISH-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"contract-first-design\",\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"api-onboarding-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"documentation\",\r\n            \"ci-cd\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"docs/api/audit/design-audit.read-only.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"spec-auto-updated\",\r\n          \"label\": \"Spec auto-updated to gateway and dev portal\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\",\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CONTRACT-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"contract-first-design\",\r\n            \"api-onboarding-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"ci-cd\",\r\n            \"gateway-config\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \".github/workflows/openapi-lint.yml\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"official-domain\",\r\n          \"label\": \"Published under official organization domain\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"documentation\",\r\n            \"runtime\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"improving\",\r\n      \"title\": \"Improving\",\r\n      \"readinessLabel\": \"Improving is Ready When...\",\r\n      \"order\": 6,\r\n      \"items\": []\r\n    }\r\n  ],\r\n  \"guidelines\": [\r\n    {\r\n      \"id\": \"REST-CONTRACT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST implement endpoints, parameters, request bodies, response bodies, and error responses as defined in the validated OpenAPI contract.\",\r\n      \"relatedAuditItems\": [\r\n        \"spec-contains-schemas\",\r\n        \"schema-and-examples-pass\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CONTRACT-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST keep the implementation, published OpenAPI description, gateway configuration, and developer portal documentation aligned on every change.\",\r\n      \"relatedAuditItems\": [\r\n        \"docs-auto-generated\",\r\n        \"spec-auto-updated\",\r\n        \"spec-validated-on-change\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-VALIDATION-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST validate path parameters, query parameters, headers, and JSON request bodies against the OpenAPI schema before business processing.\",\r\n      \"relatedAuditItems\": [\r\n        \"mandatory-fields-specified\",\r\n        \"400-errors-specific\",\r\n        \"inputs-auto-validated\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DOMAIN-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST expose business-oriented resources and attributes rather than raw backend tables, internal service payloads, or system-specific field names.\",\r\n      \"relatedAuditItems\": [\r\n        \"based-on-clear-business-needs\",\r\n        \"hides-raw-backend-data\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DOMAIN-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST preserve validated meanings of entities, attributes, statuses, and source-of-truth rules across all endpoints and operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"design-consistent\",\r\n        \"general-data-uses-standard-values\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-NAMING-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST use descriptive English names for resources and attributes.\",\r\n      \"relatedAuditItems\": [\r\n        \"descriptive-english-naming\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-NAMING-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST avoid unexplained acronyms in public field and resource names.\",\r\n      \"relatedAuditItems\": [\r\n        \"field-names-avoid-acronyms\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DATA-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST use ISO date-time values with timezone information where dates are exposed.\",\r\n      \"relatedAuditItems\": [\r\n        \"dates-use-iso\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DATA-02\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API SHOULD use standard codes, controlled vocabularies, and standardized value sets where applicable.\",\r\n      \"relatedAuditItems\": [\r\n        \"general-data-uses-standard-values\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API MUST describe the business value and feature intent of each endpoint or capability.\",\r\n      \"relatedAuditItems\": [\r\n        \"endpoint-descriptions-present\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API MUST include examples for endpoints, request bodies, response bodies, and key attributes.\",\r\n      \"relatedAuditItems\": [\r\n        \"examples-present\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-03\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API SHOULD use consistent pagination, filtering, sorting, and response conventions across resources.\",\r\n      \"relatedAuditItems\": [\r\n        \"design-consistent\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-GET-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use GET for safe read-only operations and MUST NOT define a request body for GET operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-no-request-body\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-POST-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use POST for resource creation and other non-idempotent operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"post-for-create-update\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-PUT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use PUT only for full resource replacement.\",\r\n      \"relatedAuditItems\": [\r\n        \"post-for-create-update\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-DELETE-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use DELETE to remove resources.\",\r\n      \"relatedAuditItems\": [\r\n        \"delete-for-remove\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PATH-01\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"resource-modeling\",\r\n      \"requirement\": \"The REST API SHOULD keep endpoint paths shallow and avoid more than two resource or sub-resource levels unless explicitly justified.\",\r\n      \"relatedAuditItems\": [\r\n        \"paths-max-two-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-200-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 200 OK for successful reads and updates that include a response body.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-no-request-body\",\r\n        \"post-returns-200\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-201-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 201 Created and the created resource identifier when a new resource is created.\",\r\n      \"relatedAuditItems\": [\r\n        \"create-returns-identifiers\",\r\n        \"post-returns-201\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-204-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 204 No Content for successful delete operations that do not return a body.\",\r\n      \"relatedAuditItems\": [\r\n        \"delete-returns-204\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-204-02\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API SHOULD return 204 No Content for successful operations that intentionally return no response body.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-empty-returns-204\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-400-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST define 400 Bad Request responses with specific and actionable validation error information.\",\r\n      \"relatedAuditItems\": [\r\n        \"400-errors-specific\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-401-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST return 401 Unauthorized for missing or invalid credentials.\",\r\n      \"relatedAuditItems\": [\r\n        \"401-unauthorized\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-403-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST return 403 Forbidden for authenticated clients lacking sufficient permission.\",\r\n      \"relatedAuditItems\": [\r\n        \"403-forbidden\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-VERSION-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"versioning\",\r\n      \"requirement\": \"The REST API MUST define a versioning strategy before production release, and the strategy MUST be supportable by the API gateway.\",\r\n      \"relatedAuditItems\": [\r\n        \"versioning-decided\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST require authentication for protected endpoints.\",\r\n      \"relatedAuditItems\": [\r\n        \"auth-protection\",\r\n        \"401-unauthorized\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST use token-based authentication or another approved modern authentication mechanism for protected endpoints.\",\r\n      \"relatedAuditItems\": [\r\n        \"token-auth\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-03\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST enforce object-level and function-level authorization on every protected operation.\",\r\n      \"relatedAuditItems\": [\r\n        \"401-unauthorized\",\r\n        \"403-forbidden\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-04\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST mitigate OWASP API risks including broken object level authorization, broken function level authorization, injection, and unrestricted resource consumption.\",\r\n      \"relatedAuditItems\": [\r\n        \"auth-protection\",\r\n        \"rate-limits-enforced\",\r\n        \"no-sensitive-data-in-urls\",\r\n        \"message-integrity\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-05\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST use HTTPS or another approved encrypted protocol for all traffic.\",\r\n      \"relatedAuditItems\": [\r\n        \"uses-https\",\r\n        \"encryption-in-transit\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-06\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST NOT expose sensitive information in URLs, query strings, logs, or unnecessary response fields.\",\r\n      \"relatedAuditItems\": [\r\n        \"no-sensitive-data-in-urls\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-07\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API SHOULD use UUIDs or other non-sequential public identifiers where direct database identifiers would increase exposure risk.\",\r\n      \"relatedAuditItems\": [\r\n        \"pseudo-identifiers\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-08\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST implement CSRF protection where relevant to the authentication model and client interaction pattern.\",\r\n      \"relatedAuditItems\": [\r\n        \"csrf-protection\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CAPACITY-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"resilience-capacity\",\r\n      \"requirement\": \"The REST API MUST define and enforce rate limits, throttling, or quotas according to capacity expectations.\",\r\n      \"relatedAuditItems\": [\r\n        \"rate-limits-enforced\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CAPACITY-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"resilience-capacity\",\r\n      \"requirement\": \"The REST API MUST implement resilience controls such as timeouts, fallback behavior, and degradation handling according to business impact.\",\r\n      \"relatedAuditItems\": [\r\n        \"only-via-gateway\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-OBS-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"observability\",\r\n      \"requirement\": \"The REST API MUST implement logs, metrics, and monitoring needed to observe validation failures, auth failures, traffic, latency, and dependency health.\",\r\n      \"relatedAuditItems\": [\r\n        \"rate-limits-enforced\",\r\n        \"message-integrity\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be published through an API management platform.\",\r\n      \"relatedAuditItems\": [\r\n        \"published-via-api-management\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be accessible only through approved API gateway paths and managed entry points.\",\r\n      \"relatedAuditItems\": [\r\n        \"only-via-gateway\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-03\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API SHOULD be visible in a developer portal with documentation generated from the contract.\",\r\n      \"relatedAuditItems\": [\r\n        \"visible-in-dev-portal\",\r\n        \"docs-auto-generated\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-04\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be published under an approved organizational domain.\",\r\n      \"relatedAuditItems\": [\r\n        \"official-domain\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-AUDIT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST validate the specification, schema, and examples on every change.\",\r\n      \"relatedAuditItems\": [\r\n        \"spec-validated-on-change\",\r\n        \"schema-and-examples-pass\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-AUDIT-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST pass concept, design, security, and production-readiness checks before release.\",\r\n      \"relatedAuditItems\": [\r\n        \"concept-items-audited\",\r\n        \"design-items-audited\"\r\n      ]\r\n    }\r\n  ]\r\n}\r\n",
                  "draft": false
                },
                {
                  "id": "api-compliance-best-practices",
                  "slug": "resources/api-compliance-best-practices",
                  "title": "API Compliance Best Practices",
                  "description": "Ensure APIs meet legal, regulatory, and internal compliance through documentation, controls, and automated validations.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 104,
                  "outcomes": [
                    "Shared understanding of the purpose and use of API Compliance Best Practices",
                    "A consistent approach to applying API Compliance Best Practices",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Document compliance measures and ensure they are communicated to stakeholders and consumers.",
                    "Implement measures to ensure APIs comply with these requirements, including data encryption, access controls, and audit trails.",
                    "Use checklists, linters, and testing tools to verify consistency and conformance with standards."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                }
              ],
              "evidence": [
                "audit-report",
                "compliance-report",
                "security-report",
                "test-report"
              ]
            },
            {
              "index": 7,
              "id": "api-publishing",
              "slug": "method/api-publishing",
              "icon": "deployed-code-outline",
              "title": "Integration Publishing & Enablement",
              "description": "Publish the integration capability so teams can discover it, evaluate it, request access, complete onboarding, reuse it, and get support.",
              "whyItMatters": "Reusable capabilities only create value when consumers can find them, understand their interface contract and service expectations, request access, and know who owns support and lifecycle decisions.",
              "applyInWork": "Publish ownership, documentation, onboarding, support contacts, service expectations, lifecycle status, and access request paths.",
              "outcomes": [
                "A discoverable reusable capability",
                "Clear onboarding, access, support, and service expectations",
                "Lifecycle and ownership information available to consumers and governance teams",
                "Consumers enabled to use and reuse the capability"
              ],
              "steps": [
                {
                  "text": "Publish capability information to the appropriate catalogs, portals, gateways, or environments to support reuse by multiple consumers.",
                  "resourceId": "apiops-CI-CD-for-apis",
                  "resourceTitle": "APIOps CI/CD For APIs",
                  "canvasId": null
                },
                {
                  "text": "Document how consumers find and use the capability, including onboarding processes and registration.",
                  "resourceId": "api-onboarding-best-practices",
                  "resourceTitle": "API Onboarding Best Practices",
                  "canvasId": null
                },
                {
                  "text": "Ensure security models, access configuration, and legal terms are clear and accessible to consumers.",
                  "resourceId": "api-audit-checklist",
                  "resourceTitle": "API Audit Checklist",
                  "canvasId": null
                }
              ],
              "questions": [
                "Publish capability information to the appropriate catalogs, portals, gateways, or environments to support reuse by multiple consumers.",
                "Document how consumers find and use the capability, including onboarding processes and registration.",
                "Ensure security models, access configuration, and legal terms are clear and accessible to consumers.",
                "Publish ownership, documentation, onboarding, support contacts, service expectations, lifecycle status, and access request paths.",
                "Reusable capabilities only create value when consumers can find them, understand their interface contract and service expectations, request access, and know who owns support and lifecycle decisions."
              ],
              "criteria": [
                "audit-passed",
                "audit-reports-shared",
                "api-ready-for-publishing",
                "api-documentation-ready"
              ],
              "criteriaDetails": [
                {
                  "id": "audit-passed",
                  "title": "The solution passes quality, security, compliance, and readiness checks.",
                  "description": "The API passes compliance, security, and audit checks."
                },
                {
                  "id": "audit-reports-shared",
                  "title": "Audit findings and remediation decisions are shared with the relevant stakeholders.",
                  "description": "Audit findings and remediation decisions are shared with the relevant stakeholders."
                },
                {
                  "id": "api-ready-for-publishing",
                  "title": "The capability is ready to be published or released through the selected delivery mechanism.",
                  "description": "The API is ready to be deployed and exposed through the intended gateways and environments."
                },
                {
                  "id": "api-documentation-ready",
                  "title": "Consumer-facing documentation and onboarding materials are ready.",
                  "description": "Consumer-facing API documentation is complete enough for publishing and onboarding."
                }
              ],
              "baseTitle": "Publishing & Enablement",
              "group": "Capability Lifecycle Core Stations",
              "lifecycleStage": "publishing",
              "stakeholders": [
                {
                  "id": "integration-architect",
                  "sourceKey": "integration-architect",
                  "sourceStakeholderId": "integration-architect",
                  "title": "Integration Architect",
                  "description": "Designs integration approaches and implementation styles that connect the capability or API with other systems.",
                  "involvement": "lead",
                  "responsibilities": []
                },
                {
                  "id": "api-consumer-specialist",
                  "sourceKey": "api-consumer-specialist",
                  "sourceStakeholderId": "api-consumer-specialist",
                  "title": "API Consumer Representative",
                  "description": "Represents the needs of developers, integrators, or other API consumers who use the API directly.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "api-devrel-specialist",
                  "sourceKey": "api-devrel-specialist",
                  "sourceStakeholderId": "api-devrel-specialist",
                  "title": "Documentation and DevRel Owner",
                  "description": "Owns onboarding content, developer communication, and documentation quality for API consumers.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "partner-specialist",
                  "sourceKey": "partner-specialist",
                  "sourceStakeholderId": "partner-specialist",
                  "title": "Partner or Vendor Manager",
                  "description": "Coordinates external partner, supplier, or vendor relationships that influence capability or API strategy and delivery.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "operations-specialist",
                  "sourceKey": "operations-specialist",
                  "sourceStakeholderId": "operations-specialist",
                  "title": "Support and Operations Owner",
                  "description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "business-owner",
                  "sourceKey": "business-owner",
                  "sourceStakeholderId": "business-owner",
                  "title": "Business Owner",
                  "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "compliance-specialist",
                  "sourceKey": "compliance-specialist",
                  "sourceStakeholderId": "compliance-specialist",
                  "title": "Compliance and Legal Specialist",
                  "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "security-specialist",
                  "sourceKey": "security-specialist",
                  "sourceStakeholderId": "security-specialist",
                  "title": "Security Specialist",
                  "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
                  "involvement": "consulted",
                  "responsibilities": []
                }
              ],
              "resources": [
                {
                  "id": "api-onboarding-best-practices",
                  "slug": "resources/api-onboarding-best-practices",
                  "title": "API Onboarding Best Practices",
                  "description": "Best practices to streamline API consumer onboarding journeys with step-by-step registration, discovery, and first-call guidance.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 121,
                  "outcomes": [
                    "Shared understanding of the purpose and use of API Onboarding Best Practices",
                    "A consistent approach to applying API Onboarding Best Practices",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Define the API consumer journey from discovery to troubleshooting, identifying key touchpoints and pain points.",
                    "Develop onboarding processes and resources to help API consumers understand how to use APIs effectively.",
                    "Document how consumers find and use the API, including onboarding processes and registration."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                },
                {
                  "id": "service-agreement-template",
                  "slug": "resources/service-agreement-template",
                  "title": "Service Agreement Template",
                  "description": "A customizable agreement format that defines expectations, SLAs, responsibilities, and access terms for API consumption.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 172,
                  "outcomes": [
                    "Shared understanding of the purpose and use of Service Agreement Template",
                    "A consistent approach to applying Service Agreement Template",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Define service agreements that outline the expectations, service levels, and responsibilities for each API.",
                    "Use standardized formats to create machine-readable service agreements that are easy to share and validate.",
                    "Ensure service agreements are reviewed and approved by stakeholders to ensure alignment and clarity."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                }
              ],
              "evidence": [
                "gateway-config",
                "developer-portal",
                "documentation",
                "release-record"
              ]
            },
            {
              "index": 8,
              "id": "monitoring-and-improving",
              "slug": "method/monitoring-and-improving",
              "icon": "analytics-outline",
              "title": "Integration Monitoring & Improvement",
              "description": "Monitor integration reliability, reuse, incidents, performance, consumer outcomes, and improvement needs.",
              "whyItMatters": "Capabilities need continuous feedback to stay reliable, valuable, cost-effective, and reusable as consumers, systems, data, and platforms change.",
              "applyInWork": "Use metrics, analytics, and engagement practices to improve the capability over time.",
              "outcomes": [
                "Measured capability health and value",
                "Improvement backlog informed by operational and consumer feedback",
                "Reuse, reliability, data quality, and cost signals available to owners",
                "Continuous improvement aligned with consumer needs"
              ],
              "steps": [
                {
                  "text": "Use metrics and analytics guidance to define capability usage, reliability, data quality, cost, adoption, and consumer-value measures.",
                  "resourceId": "api-metrics-and-analytics",
                  "resourceTitle": "API Metrics And Analytics",
                  "canvasId": null
                },
                {
                  "text": "Analyze usage metrics and incorporate consumer feedback into capability iterations.",
                  "resourceId": "api-community-engagement-strategies",
                  "resourceTitle": "API Community Engagement Strategies",
                  "canvasId": null
                },
                {
                  "text": "Establish a habit of reviewing metrics and planning continuous improvement activities.",
                  "resourceId": "apiops-CI-CD-for-apis",
                  "resourceTitle": "APIOps CI/CD For APIs",
                  "canvasId": null
                }
              ],
              "questions": [
                "Use metrics and analytics guidance to define capability usage, reliability, data quality, cost, adoption, and consumer-value measures.",
                "Analyze usage metrics and incorporate consumer feedback into capability iterations.",
                "Establish a habit of reviewing metrics and planning continuous improvement activities.",
                "Use metrics, analytics, and engagement practices to improve the capability over time.",
                "Capabilities need continuous feedback to stay reliable, valuable, cost-effective, and reusable as consumers, systems, data, and platforms change."
              ],
              "criteria": [
                "api-documentation-ready",
                "consumer-support-ready",
                "legal-compliance-clear"
              ],
              "criteriaDetails": [
                {
                  "id": "api-documentation-ready",
                  "title": "Consumer-facing documentation and onboarding materials are ready.",
                  "description": "Consumer-facing API documentation is complete enough for publishing and onboarding."
                },
                {
                  "id": "consumer-support-ready",
                  "title": "Consumer onboarding, support, and communication processes are ready.",
                  "description": "Registration, support, and communication processes are ready for API consumers."
                },
                {
                  "id": "legal-compliance-clear",
                  "title": "Legal, privacy, and compliance requirements for publishing or release are defined and understood.",
                  "description": "Legal, privacy, and compliance requirements for publishing are defined and understood."
                }
              ],
              "baseTitle": "Monitoring & Improvement",
              "group": "Capability Lifecycle Core Stations",
              "lifecycleStage": "improving",
              "stakeholders": [
                {
                  "id": "integration-architect",
                  "sourceKey": "integration-architect",
                  "sourceStakeholderId": "integration-architect",
                  "title": "Integration Architect",
                  "description": "Designs integration approaches and implementation styles that connect the capability or API with other systems.",
                  "involvement": "lead",
                  "responsibilities": []
                },
                {
                  "id": "api-consumer-specialist",
                  "sourceKey": "api-consumer-specialist",
                  "sourceStakeholderId": "api-consumer-specialist",
                  "title": "API Consumer Representative",
                  "description": "Represents the needs of developers, integrators, or other API consumers who use the API directly.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "api-engineer",
                  "sourceKey": "api-engineer",
                  "sourceStakeholderId": "api-engineer",
                  "title": "Delivery Engineer",
                  "description": "Owns implementation, automation, testing, and release flow concerns needed to deliver the capability, API, or automation reliably.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "platform-owner",
                  "sourceKey": "platform-owner",
                  "sourceStakeholderId": "platform-owner",
                  "title": "Platform Owner",
                  "description": "Owns platform capabilities, roadmap, operational model, and service expectations.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "operations-specialist",
                  "sourceKey": "operations-specialist",
                  "sourceStakeholderId": "operations-specialist",
                  "title": "Support and Operations Owner",
                  "description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "business-owner",
                  "sourceKey": "business-owner",
                  "sourceStakeholderId": "business-owner",
                  "title": "Business Owner",
                  "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "compliance-specialist",
                  "sourceKey": "compliance-specialist",
                  "sourceStakeholderId": "compliance-specialist",
                  "title": "Compliance and Legal Specialist",
                  "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "platform-architect",
                  "sourceKey": "platform-architect",
                  "sourceStakeholderId": "platform-architect",
                  "title": "Platform Architect",
                  "description": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "security-specialist",
                  "sourceKey": "security-specialist",
                  "sourceStakeholderId": "security-specialist",
                  "title": "Security Specialist",
                  "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
                  "involvement": "consulted",
                  "responsibilities": []
                }
              ],
              "resources": [
                {
                  "id": "api-metrics-and-analytics",
                  "slug": "resources/api-metrics-and-analytics",
                  "title": "API Metrics And Analytics",
                  "description": "A resource for defining, collecting, and analyzing API performance and usage data to align technical KPIs with business outcomes.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 119,
                  "outcomes": [
                    "Shared understanding of the purpose and use of API Metrics And Analytics",
                    "A consistent approach to applying API Metrics And Analytics",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Identify key performance indicators (KPIs) to measure API success against business goals.",
                    "Define and monitor performance metrics (e.g., API calls, latency, error rates) and adoption metrics (e.g., NPS).",
                    "Monitor API initiatives to ensure adherence to operating guidelines and governance practices"
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                },
                {
                  "id": "api-community-engagement-strategies",
                  "slug": "resources/api-community-engagement-strategies",
                  "title": "API Community Engagement Strategies",
                  "description": "A playbook for fostering API adoption by cultivating communities through content, support channels, feedback loops, and social engagement strategies.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 103,
                  "outcomes": [
                    "Shared understanding of the purpose and use of API Community Engagement Strategies",
                    "A consistent approach to applying API Community Engagement Strategies",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Develop marketing strategies to promote APIs to target audiences, including social media, blogs, and webinars.",
                    "Create promotional materials (e.g., case studies, success stories) that highlight the value and benefits of APIs.",
                    "Create educational materials (e.g., tutorials, documentation) that explain API features, benefits, and usage patterns.",
                    "Engage with API consumers through feedback loops, support channels, and community forums to understand their needs and improve API adoption.",
                    "Analyze API usage metrics and incorporate user feedback into API iterations."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                }
              ],
              "evidence": [
                "metrics",
                "consumer-feedback",
                "incident-report",
                "roadmap"
              ]
            }
          ]
        },
        {
          "id": "automation-cycle",
          "slug": "automation-cycle",
          "title": "Automation Cycle",
          "description": "A cycle for identifying, designing, delivering, enabling, and improving automation opportunities.",
          "purpose": "Productize automation opportunities into governed workflows with clear users, platforms, controls, delivery paths, enablement, and monitoring.",
          "audiences": [],
          "audienceStakeholders": [
            {
              "id": "automation-owner",
              "sourceKey": "automation-owner",
              "sourceStakeholderId": "automation-owner",
              "title": "Automation Owner",
              "description": "Owns automation goals, business value, priorities, controls, and lifecycle outcomes.",
              "involvement": "lead",
              "responsibilities": []
            },
            {
              "id": "business-owner",
              "sourceKey": "business-owner",
              "sourceStakeholderId": "business-owner",
              "title": "Business Owner",
              "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
              "involvement": "core",
              "responsibilities": [
                {
                  "resourceId": "customerJourneyCanvas",
                  "resourceTitle": "Customer Journey Canvas",
                  "canvasId": "customerJourneyCanvas",
                  "role": "suggested-answer-owner"
                }
              ]
            },
            {
              "id": "domain-specialist",
              "sourceKey": "domain-specialist",
              "sourceStakeholderId": "domain-specialist",
              "title": "Domain Expert",
              "description": "Brings deep knowledge of the business domain, concepts, rules, and constraints the capability or interface must reflect.",
              "involvement": "core",
              "responsibilities": [
                {
                  "resourceId": "domainCanvas",
                  "resourceTitle": "Domain Canvas",
                  "canvasId": "domainCanvas",
                  "role": "suggested-answer-owner"
                }
              ]
            },
            {
              "id": "process-owner",
              "sourceKey": "process-owner",
              "sourceStakeholderId": "process-owner",
              "title": "Process Owner",
              "description": "Owns the business process being automated, including objectives, rules, outcomes, and improvement priorities.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "customer-specialist",
              "sourceKey": "customer-specialist",
              "sourceStakeholderId": "customer-specialist",
              "title": "Customer or Partner Representative",
              "description": "Contributes the business customer or partner perspective for the journey, value, and collaboration model.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "platform-owner",
              "sourceKey": "platform-owner",
              "sourceStakeholderId": "platform-owner",
              "title": "Platform Owner",
              "description": "Owns platform capabilities, roadmap, operational model, and service expectations.",
              "involvement": "lead",
              "responsibilities": []
            },
            {
              "id": "automation-engineer",
              "sourceKey": "automation-engineer",
              "sourceStakeholderId": "automation-engineer",
              "title": "Automation Engineer",
              "description": "Implements, tests, integrates, and maintains automation solutions and supporting workflows.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "compliance-specialist",
              "sourceKey": "compliance-specialist",
              "sourceStakeholderId": "compliance-specialist",
              "title": "Compliance and Legal Specialist",
              "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "platform-architect",
              "sourceKey": "platform-architect",
              "sourceStakeholderId": "platform-architect",
              "title": "Platform Architect",
              "description": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "security-specialist",
              "sourceKey": "security-specialist",
              "sourceStakeholderId": "security-specialist",
              "title": "Security Specialist",
              "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "integration-architect",
              "sourceKey": "integration-architect",
              "sourceStakeholderId": "integration-architect",
              "title": "Integration Architect",
              "description": "Designs integration approaches and implementation styles that connect the capability or API with other systems.",
              "involvement": "core",
              "responsibilities": [
                {
                  "resourceId": "interactionCanvas",
                  "resourceTitle": "Interaction Canvas",
                  "canvasId": "interactionCanvas",
                  "role": "suggested-answer-owner"
                }
              ]
            },
            {
              "id": "operations-specialist",
              "sourceKey": "operations-specialist",
              "sourceStakeholderId": "operations-specialist",
              "title": "Support and Operations Owner",
              "description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "governance-specialist",
              "sourceKey": "governance-specialist",
              "sourceStakeholderId": "governance-specialist",
              "title": "API Governance Owner",
              "description": "Represents review, audit, and organization-wide governance practices for API quality and conformity.",
              "involvement": "lead",
              "responsibilities": []
            },
            {
              "id": "api-devrel-specialist",
              "sourceKey": "api-devrel-specialist",
              "sourceStakeholderId": "api-devrel-specialist",
              "title": "Documentation and DevRel Owner",
              "description": "Owns onboarding content, developer communication, and documentation quality for API consumers.",
              "involvement": "core",
              "responsibilities": []
            }
          ],
          "entryCriteria": [
            "business-goals-defined",
            "stakeholder-approval"
          ],
          "exitCriteria": [
            "design-reflects-business-value",
            "automation-workflow-validated",
            "audit-passed"
          ],
          "entryCriteriaDetails": [
            {
              "id": "business-goals-defined",
              "title": "Business goals are defined.",
              "description": "Business goals are defined."
            },
            {
              "id": "stakeholder-approval",
              "title": "Relevant stakeholders agree this capability opportunity is worth exploring and prioritizing.",
              "description": "Relevant stakeholders agree this API opportunity is worth exploring and prioritizing."
            }
          ],
          "exitCriteriaDetails": [
            {
              "id": "design-reflects-business-value",
              "title": "The interface design and exposed capabilities trace back to business value and consumer needs.",
              "description": "The API design and exposed capabilities clearly trace back to business value and user needs."
            },
            {
              "id": "automation-workflow-validated",
              "title": "The workflow, rules, integrations, and relevant interface contracts have been validated and tested.",
              "description": "The workflow, rules, integrations, and relevant interface contracts have been validated and tested."
            },
            {
              "id": "audit-passed",
              "title": "The solution passes quality, security, compliance, and readiness checks.",
              "description": "The API passes compliance, security, and audit checks."
            }
          ],
          "questionnaireResources": [
            {
              "stationId": "api-product-strategy",
              "stationTitle": "Automation Opportunity Strategy",
              "resourceId": "customerJourneyCanvas",
              "resourceTitle": "Customer Journey Canvas",
              "canvasId": "customerJourneyCanvas",
              "suggestedAnswerOwner": {
                "id": "business-owner",
                "sourceKey": "business-owner",
                "sourceStakeholderId": "business-owner",
                "title": "Business Owner",
                "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
                "involvement": "core",
                "responsibilities": [
                  {
                    "resourceId": "customerJourneyCanvas",
                    "resourceTitle": "Customer Journey Canvas",
                    "canvasId": "customerJourneyCanvas",
                    "role": "suggested-answer-owner"
                  }
                ]
              }
            },
            {
              "stationId": "api-product-strategy",
              "stationTitle": "Automation Opportunity Strategy",
              "resourceId": "domainCanvas",
              "resourceTitle": "Domain Canvas",
              "canvasId": "domainCanvas",
              "suggestedAnswerOwner": {
                "id": "domain-specialist",
                "sourceKey": "domain-specialist",
                "sourceStakeholderId": "domain-specialist",
                "title": "Domain Expert",
                "description": "Brings deep knowledge of the business domain, concepts, rules, and constraints the capability or interface must reflect.",
                "involvement": "core",
                "responsibilities": [
                  {
                    "resourceId": "domainCanvas",
                    "resourceTitle": "Domain Canvas",
                    "canvasId": "domainCanvas",
                    "role": "suggested-answer-owner"
                  }
                ]
              }
            },
            {
              "stationId": "api-consumer-experience",
              "stationTitle": "Process & User Requirements",
              "resourceId": "consumerExperienceRequirementsCanvas",
              "resourceTitle": "Consumer Experience Requirements Canvas",
              "canvasId": "consumerExperienceRequirementsCanvas",
              "suggestedAnswerOwner": {
                "id": "api-consumer-specialist",
                "sourceKey": "api-consumer-specialist",
                "sourceStakeholderId": "api-consumer-specialist",
                "title": "API Consumer Representative",
                "description": "Represents the needs of developers, integrators, or other API consumers who use the API directly.",
                "involvement": "consulted",
                "responsibilities": [
                  {
                    "resourceId": "consumerExperienceRequirementsCanvas",
                    "resourceTitle": "Consumer Experience Requirements Canvas",
                    "canvasId": "consumerExperienceRequirementsCanvas",
                    "role": "suggested-answer-owner"
                  }
                ]
              }
            },
            {
              "stationId": "api-design",
              "stationTitle": "Automation Workflow Design",
              "resourceId": "interactionCanvas",
              "resourceTitle": "Interaction Canvas",
              "canvasId": "interactionCanvas",
              "suggestedAnswerOwner": {
                "id": "integration-architect",
                "sourceKey": "integration-architect",
                "sourceStakeholderId": "integration-architect",
                "title": "Integration Architect",
                "description": "Designs integration approaches and implementation styles that connect the capability or API with other systems.",
                "involvement": "core",
                "responsibilities": [
                  {
                    "resourceId": "interactionCanvas",
                    "resourceTitle": "Interaction Canvas",
                    "canvasId": "interactionCanvas",
                    "role": "suggested-answer-owner"
                  }
                ]
              }
            }
          ],
          "stations": [
            {
              "index": 1,
              "id": "api-product-strategy",
              "slug": "method/api-product-strategy",
              "icon": "strategy-outline",
              "title": "Automation Opportunity Strategy",
              "description": "Identify and prioritize automation opportunities by value, feasibility, risk, ownership, and expected process impact.",
              "whyItMatters": "Integration and API work often jumps too quickly to a technical pattern. This station keeps the team focused on the business journey, domain meaning, value, reuse potential, ownership, and viability before selecting APIs, events, files, streams, data products, or direct integration.",
              "applyInWork": "Use shared journey, domain, value proposition, and business model canvases to gather technology-agnostic requirements and decide whether the capability should be reusable.",
              "outcomes": [
                "A technology-agnostic capability opportunity statement",
                "Shared understanding of consumers, producers, domain concepts, and reuse potential",
                "A capability value proposition and business model before architecture selection"
              ],
              "steps": [
                {
                  "text": "Map the customer or partner journey that creates the capability need and reveals tasks, pains, gains, inputs, outputs, and decision points.",
                  "resourceId": "customerJourneyCanvas",
                  "resourceTitle": "Customer Journey Canvas",
                  "canvasId": "customerJourneyCanvas"
                },
                {
                  "text": "Define the core entities, attributes, relationships, ownership, and business rules that the capability must respect.",
                  "resourceId": "domainCanvas",
                  "resourceTitle": "Domain Canvas",
                  "canvasId": "domainCanvas"
                },
                {
                  "text": "Use the Capability Value Proposition Canvas to capture consumer tasks, gains, pains, and reusable capability features without naming the delivery technology too early.",
                  "resourceId": "apiValuePropositionCanvas",
                  "resourceTitle": "API Value Proposition Canvas",
                  "canvasId": "apiValuePropositionCanvas"
                },
                {
                  "text": "Use the Capability Business Model Canvas to clarify ownership, partners, channels, costs, benefits, support, and lifecycle expectations for the reusable capability.",
                  "resourceId": "apiBusinessModelCanvas",
                  "resourceTitle": "API Business Model Canvas",
                  "canvasId": "apiBusinessModelCanvas"
                }
              ],
              "questions": [
                "Map the customer or partner journey that creates the capability need and reveals tasks, pains, gains, inputs, outputs, and decision points.",
                "Define the core entities, attributes, relationships, ownership, and business rules that the capability must respect.",
                "Use the Capability Value Proposition Canvas to capture consumer tasks, gains, pains, and reusable capability features without naming the delivery technology too early.",
                "Use the Capability Business Model Canvas to clarify ownership, partners, channels, costs, benefits, support, and lifecycle expectations for the reusable capability.",
                "Use shared journey, domain, value proposition, and business model canvases to gather technology-agnostic requirements and decide whether the capability should be reusable.",
                "Integration and API work often jumps too quickly to a technical pattern. This station keeps the team focused on the business journey, domain meaning, value, reuse potential, ownership, and viability before selecting APIs, events, files, streams, data products, or direct integration."
              ],
              "criteria": [
                "metrics-feedback-available",
                "business-goals-defined",
                "market-research-done",
                "stakeholder-approval"
              ],
              "criteriaDetails": [
                {
                  "id": "metrics-feedback-available",
                  "title": "Relevant market signals, feedback, or operational insights are available to guide this capability opportunity.",
                  "description": "Relevant market signals, feedback, or operational insights are available to guide this API opportunity."
                },
                {
                  "id": "business-goals-defined",
                  "title": "Business goals are defined.",
                  "description": "Business goals are defined."
                },
                {
                  "id": "market-research-done",
                  "title": "Market research identifies capability opportunities.",
                  "description": "Market research identifies API opportunities."
                },
                {
                  "id": "stakeholder-approval",
                  "title": "Relevant stakeholders agree this capability opportunity is worth exploring and prioritizing.",
                  "description": "Relevant stakeholders agree this API opportunity is worth exploring and prioritizing."
                }
              ],
              "baseTitle": "Strategy",
              "group": "Capability Lifecycle Core Stations",
              "lifecycleStage": "strategy",
              "stakeholders": [
                {
                  "id": "automation-owner",
                  "sourceKey": "automation-owner",
                  "sourceStakeholderId": "automation-owner",
                  "title": "Automation Owner",
                  "description": "Owns automation goals, business value, priorities, controls, and lifecycle outcomes.",
                  "involvement": "lead",
                  "responsibilities": []
                },
                {
                  "id": "business-owner",
                  "sourceKey": "business-owner",
                  "sourceStakeholderId": "business-owner",
                  "title": "Business Owner",
                  "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
                  "involvement": "core",
                  "responsibilities": [
                    {
                      "resourceId": "customerJourneyCanvas",
                      "resourceTitle": "Customer Journey Canvas",
                      "canvasId": "customerJourneyCanvas",
                      "role": "suggested-answer-owner"
                    }
                  ]
                },
                {
                  "id": "domain-specialist",
                  "sourceKey": "domain-specialist",
                  "sourceStakeholderId": "domain-specialist",
                  "title": "Domain Expert",
                  "description": "Brings deep knowledge of the business domain, concepts, rules, and constraints the capability or interface must reflect.",
                  "involvement": "core",
                  "responsibilities": [
                    {
                      "resourceId": "domainCanvas",
                      "resourceTitle": "Domain Canvas",
                      "canvasId": "domainCanvas",
                      "role": "suggested-answer-owner"
                    }
                  ]
                },
                {
                  "id": "process-owner",
                  "sourceKey": "process-owner",
                  "sourceStakeholderId": "process-owner",
                  "title": "Process Owner",
                  "description": "Owns the business process being automated, including objectives, rules, outcomes, and improvement priorities.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "automation-engineer",
                  "sourceKey": "automation-engineer",
                  "sourceStakeholderId": "automation-engineer",
                  "title": "Automation Engineer",
                  "description": "Implements, tests, integrates, and maintains automation solutions and supporting workflows.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "compliance-specialist",
                  "sourceKey": "compliance-specialist",
                  "sourceStakeholderId": "compliance-specialist",
                  "title": "Compliance and Legal Specialist",
                  "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "platform-owner",
                  "sourceKey": "platform-owner",
                  "sourceStakeholderId": "platform-owner",
                  "title": "Platform Owner",
                  "description": "Owns platform capabilities, roadmap, operational model, and service expectations.",
                  "involvement": "consulted",
                  "responsibilities": []
                }
              ],
              "resources": [
                {
                  "id": "customerJourneyCanvas",
                  "slug": "resources/customer-journey-canvas",
                  "title": "Customer Journey Canvas",
                  "description": "Map customer, partner, or consumer journeys to identify needs, pain points, gains, inputs, outputs, and experience expectations.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 1,
                  "outcomes": [
                    "Shared understanding of the customer, partner, or consumer journey",
                    "Needs, pain points, gains, inputs, and outputs documented",
                    "Journey evidence available for capability, requirements, and architecture decisions"
                  ],
                  "steps": [
                    "Define customer persona",
                    "Identify triggers for the journey",
                    "Describe the journey's end",
                    "Map journey steps with inputs/outputs",
                    "Identify customer pains",
                    "Summarize customer gains",
                    "Define necessary inputs and resulting outputs",
                    "Define interactions and processing expectations for each step"
                  ],
                  "canvasId": "customerJourneyCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "domainCanvas",
                  "slug": "resources/domain-canvas",
                  "title": "Domain Canvas",
                  "description": "A modeling tool to define and communicate the key entities and relationships in your domain, ensuring semantic consistency across capabilities, integrations, APIs, data products, and services.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 152,
                  "outcomes": [
                    "Shared domain model and terminology",
                    "Core entities, relationships, rules, and ownership clarified",
                    "Semantic consistency across capabilities, integrations, APIs, data products, and services"
                  ],
                  "steps": [
                    "Define core entities, their attributes, and relationships to create a shared conceptual understanding across capabilities, integrations, APIs, data products, and services."
                  ],
                  "canvasId": "domainCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "capabilityValuePropositionCanvas",
                  "slug": "resources/capability-value-proposition-canvas",
                  "title": "Capability Value Proposition Canvas",
                  "description": "A technology-agnostic canvas for mapping consumer tasks, gains, pains, and candidate reusable capabilities before selecting an implementation style.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 2.1,
                  "outcomes": [
                    "Clear reusable capability value proposition",
                    "Consumer tasks, gains, and pains captured without assuming a technology",
                    "Candidate reusable capabilities identified for architecture evaluation"
                  ],
                  "steps": [
                    "List the consumer tasks and outcomes the capability should support.",
                    "Identify gain-enabling capability features.",
                    "Identify pain-relieving capability features.",
                    "Group the features into candidate reusable capabilities."
                  ],
                  "canvasId": "capabilityValuePropositionCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                }
              ],
              "evidence": [
                "design-artifact",
                "documentation",
                "research",
                "roadmap"
              ]
            },
            {
              "index": 2,
              "id": "api-consumer-experience",
              "slug": "method/api-consumer-experience",
              "icon": "deployed-code-account-outline",
              "title": "Process & User Requirements",
              "description": "Capture process users, roles, handoffs, exceptions, constraints, and service expectations before designing the automation.",
              "whyItMatters": "The right architecture depends on consumer goals, onboarding expectations, service levels, data quality needs, change tolerance, observability, support, and producer constraints.",
              "applyInWork": "Use consumer experience and onboarding guidance to make expectations explicit for both consumers and producers.",
              "outcomes": [
                "Documented consumer requirements and onboarding expectations",
                "Clear producer responsibilities and support expectations",
                "Architecture-relevant constraints ready for decision making",
                "Improved adoption through consumer empathy, standards, and producer clarity"
              ],
              "steps": [
                {
                  "text": "Use the Consumer Experience Requirements Canvas to capture consumer goals, availability, freshness, volume, performance, data quality, security, onboarding, change, observability, and recovery expectations.",
                  "resourceId": "apiValuePropositionCanvas",
                  "resourceTitle": "API Value Proposition Canvas",
                  "canvasId": "apiValuePropositionCanvas"
                },
                {
                  "text": "Use onboarding guidance to describe how consumers will find, request, test, get approved for, and start using the capability.",
                  "resourceId": "customerJourneyCanvas",
                  "resourceTitle": "Customer Journey Canvas",
                  "canvasId": "customerJourneyCanvas"
                },
                {
                  "text": "Use the resulting journey and requirements to improve onboarding, documentation, support, and feedback loops for capability consumers.",
                  "resourceId": "api-onboarding-best-practices",
                  "resourceTitle": "API Onboarding Best Practices",
                  "canvasId": null
                }
              ],
              "questions": [
                "Use the Consumer Experience Requirements Canvas to capture consumer goals, availability, freshness, volume, performance, data quality, security, onboarding, change, observability, and recovery expectations.",
                "Use onboarding guidance to describe how consumers will find, request, test, get approved for, and start using the capability.",
                "Use the resulting journey and requirements to improve onboarding, documentation, support, and feedback loops for capability consumers.",
                "Use consumer experience and onboarding guidance to make expectations explicit for both consumers and producers.",
                "The right architecture depends on consumer goals, onboarding expectations, service levels, data quality needs, change tolerance, observability, support, and producer constraints."
              ],
              "criteria": [
                "api-opportunity-documented",
                "api-reusability",
                "hide-backend-discrepancies",
                "value-prop-validated",
                "consumer-segments-identified",
                "api-roadmap-defined"
              ],
              "criteriaDetails": [
                {
                  "id": "api-opportunity-documented",
                  "title": "Capability opportunity is identified and documented.",
                  "description": "Individual API opportunities are identified and documented."
                },
                {
                  "id": "api-reusability",
                  "title": "The capability addresses a clear business need and is reusable by its intended consumers.",
                  "description": "The API meets a clear business need and is reusable for multiple API consumers."
                },
                {
                  "id": "hide-backend-discrepancies",
                  "title": "The selected interface provides an appropriate abstraction for consumers.",
                  "description": "The API is intended to shield consumers from backend complexity and inconsistencies."
                },
                {
                  "id": "value-prop-validated",
                  "title": "The capability value proposition has been validated with business and consumer stakeholders.",
                  "description": "The API value proposition has been reviewed and validated with the relevant business and consumer stakeholders."
                },
                {
                  "id": "consumer-segments-identified",
                  "title": "Consumer segments are identified.",
                  "description": "API consumer segments (internal and external) are identified."
                },
                {
                  "id": "api-roadmap-defined",
                  "title": "A high-level implementation roadmap is defined.",
                  "description": "High-level roadmaps for API development are established."
                }
              ],
              "baseTitle": "Consumer Requirements & Onboarding",
              "group": "Capability Lifecycle Core Stations",
              "lifecycleStage": "strategy",
              "stakeholders": [
                {
                  "id": "process-owner",
                  "sourceKey": "process-owner",
                  "sourceStakeholderId": "process-owner",
                  "title": "Process Owner",
                  "description": "Owns the business process being automated, including objectives, rules, outcomes, and improvement priorities.",
                  "involvement": "lead",
                  "responsibilities": []
                },
                {
                  "id": "automation-owner",
                  "sourceKey": "automation-owner",
                  "sourceStakeholderId": "automation-owner",
                  "title": "Automation Owner",
                  "description": "Owns automation goals, business value, priorities, controls, and lifecycle outcomes.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "customer-specialist",
                  "sourceKey": "customer-specialist",
                  "sourceStakeholderId": "customer-specialist",
                  "title": "Customer or Partner Representative",
                  "description": "Contributes the business customer or partner perspective for the journey, value, and collaboration model.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "domain-specialist",
                  "sourceKey": "domain-specialist",
                  "sourceStakeholderId": "domain-specialist",
                  "title": "Domain Expert",
                  "description": "Brings deep knowledge of the business domain, concepts, rules, and constraints the capability or interface must reflect.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "api-consumer-specialist",
                  "sourceKey": "api-consumer-specialist",
                  "sourceStakeholderId": "api-consumer-specialist",
                  "title": "API Consumer Representative",
                  "description": "Represents the needs of developers, integrators, or other API consumers who use the API directly.",
                  "involvement": "consulted",
                  "responsibilities": [
                    {
                      "resourceId": "consumerExperienceRequirementsCanvas",
                      "resourceTitle": "Consumer Experience Requirements Canvas",
                      "canvasId": "consumerExperienceRequirementsCanvas",
                      "role": "suggested-answer-owner"
                    }
                  ]
                },
                {
                  "id": "compliance-specialist",
                  "sourceKey": "compliance-specialist",
                  "sourceStakeholderId": "compliance-specialist",
                  "title": "Compliance and Legal Specialist",
                  "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "operations-specialist",
                  "sourceKey": "operations-specialist",
                  "sourceStakeholderId": "operations-specialist",
                  "title": "Support and Operations Owner",
                  "description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
                  "involvement": "consulted",
                  "responsibilities": []
                }
              ],
              "resources": [
                {
                  "id": "consumerExperienceRequirementsCanvas",
                  "slug": "resources/consumer-experience-requirements-canvas",
                  "title": "Consumer Experience Requirements Canvas",
                  "description": "A requirements canvas for consumer experience and non-functional needs that should guide the later architecture and implementation-style decision.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 3.2,
                  "outcomes": [
                    "Technology-agnostic consumer and service requirements",
                    "Experience and non-functional needs captured before design starts",
                    "Architecture implications documented for implementation-style selection"
                  ],
                  "steps": [
                    "Capture consumer goals and usage context.",
                    "Document availability, timeliness, volume, performance, data quality, and consistency expectations.",
                    "Document security, privacy, onboarding, change, observability, support, and recovery expectations.",
                    "Summarize what the requirements imply for possible implementation styles."
                  ],
                  "canvasId": "consumerExperienceRequirementsCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                }
              ],
              "evidence": [
                "design-artifact",
                "documentation",
                "consumer-feedback"
              ]
            },
            {
              "index": 3,
              "id": "api-platform-architecture",
              "slug": "method/api-platform-architecture",
              "icon": "code-blocks-outline",
              "title": "Automation Platform Decision",
              "description": "Choose the automation platform, runtime, integration approach, governance controls, and operating constraints.",
              "whyItMatters": "Architecture choices should follow from evidence about business impact, locations, trust boundaries, capacity, latency, data ownership, consistency, operability, security, privacy, governance, and cost.",
              "applyInWork": "Compare viable architecture styles against the gathered requirements and document the selected pattern and rationale.",
              "outcomes": [
                "A justified architecture choice",
                "Documented risks, locations, capacity, security, privacy, and operability constraints",
                "Clear rationale for API, event, file, stream, data product, direct integration, or hybrid implementation style"
              ],
              "steps": [
                {
                  "text": "Use the Business Impact Canvas to identify availability, security, and data risks that influence architecture options.",
                  "resourceId": "businessImpactCanvas",
                  "resourceTitle": "Business Impact Canvas",
                  "canvasId": "businessImpactCanvas"
                },
                {
                  "text": "Use the Locations Canvas to capture geopolitical, regulatory, network, residency, and trust-boundary constraints.",
                  "resourceId": "locationsCanvas",
                  "resourceTitle": "Location Canvas",
                  "canvasId": "locationsCanvas"
                },
                {
                  "text": "Use the Capacity Canvas to capture current and future volumes, peaks, latency, caching, rate limiting, and scaling expectations.",
                  "resourceId": "capacityCanvas",
                  "resourceTitle": "Capacity Canvas",
                  "canvasId": "capacityCanvas"
                },
                {
                  "text": "Use metrics and analytics guidance to define how the chosen capability will be monitored and improved.",
                  "resourceId": "api-metrics-and-analytics",
                  "resourceTitle": "API Metrics And Analytics",
                  "canvasId": null
                }
              ],
              "questions": [
                "Use the Business Impact Canvas to identify availability, security, and data risks that influence architecture options.",
                "Use the Locations Canvas to capture geopolitical, regulatory, network, residency, and trust-boundary constraints.",
                "Use the Capacity Canvas to capture current and future volumes, peaks, latency, caching, rate limiting, and scaling expectations.",
                "Use metrics and analytics guidance to define how the chosen capability will be monitored and improved.",
                "Compare viable architecture styles against the gathered requirements and document the selected pattern and rationale.",
                "Architecture choices should follow from evidence about business impact, locations, trust boundaries, capacity, latency, data ownership, consistency, operability, security, privacy, governance, and cost."
              ],
              "criteria": [
                "api-reusability",
                "hide-backend-discrepancies",
                "value-prop-validated",
                "consumer-segments-identified",
                "api-roadmap-defined"
              ],
              "criteriaDetails": [
                {
                  "id": "api-reusability",
                  "title": "The capability addresses a clear business need and is reusable by its intended consumers.",
                  "description": "The API meets a clear business need and is reusable for multiple API consumers."
                },
                {
                  "id": "hide-backend-discrepancies",
                  "title": "The selected interface provides an appropriate abstraction for consumers.",
                  "description": "The API is intended to shield consumers from backend complexity and inconsistencies."
                },
                {
                  "id": "value-prop-validated",
                  "title": "The capability value proposition has been validated with business and consumer stakeholders.",
                  "description": "The API value proposition has been reviewed and validated with the relevant business and consumer stakeholders."
                },
                {
                  "id": "consumer-segments-identified",
                  "title": "Consumer segments are identified.",
                  "description": "API consumer segments (internal and external) are identified."
                },
                {
                  "id": "api-roadmap-defined",
                  "title": "A high-level implementation roadmap is defined.",
                  "description": "High-level roadmaps for API development are established."
                }
              ],
              "baseTitle": "Architecture & Platform Decisions",
              "group": "Capability Lifecycle Core Stations",
              "lifecycleStage": "architecture",
              "stakeholders": [
                {
                  "id": "platform-owner",
                  "sourceKey": "platform-owner",
                  "sourceStakeholderId": "platform-owner",
                  "title": "Platform Owner",
                  "description": "Owns platform capabilities, roadmap, operational model, and service expectations.",
                  "involvement": "lead",
                  "responsibilities": []
                },
                {
                  "id": "automation-engineer",
                  "sourceKey": "automation-engineer",
                  "sourceStakeholderId": "automation-engineer",
                  "title": "Automation Engineer",
                  "description": "Implements, tests, integrates, and maintains automation solutions and supporting workflows.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "automation-owner",
                  "sourceKey": "automation-owner",
                  "sourceStakeholderId": "automation-owner",
                  "title": "Automation Owner",
                  "description": "Owns automation goals, business value, priorities, controls, and lifecycle outcomes.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "compliance-specialist",
                  "sourceKey": "compliance-specialist",
                  "sourceStakeholderId": "compliance-specialist",
                  "title": "Compliance and Legal Specialist",
                  "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "platform-architect",
                  "sourceKey": "platform-architect",
                  "sourceStakeholderId": "platform-architect",
                  "title": "Platform Architect",
                  "description": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "security-specialist",
                  "sourceKey": "security-specialist",
                  "sourceStakeholderId": "security-specialist",
                  "title": "Security Specialist",
                  "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "integration-architect",
                  "sourceKey": "integration-architect",
                  "sourceStakeholderId": "integration-architect",
                  "title": "Integration Architect",
                  "description": "Designs integration approaches and implementation styles that connect the capability or API with other systems.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "operations-specialist",
                  "sourceKey": "operations-specialist",
                  "sourceStakeholderId": "operations-specialist",
                  "title": "Support and Operations Owner",
                  "description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
                  "involvement": "consulted",
                  "responsibilities": []
                }
              ],
              "resources": [
                {
                  "id": "businessImpactCanvas",
                  "slug": "resources/business-impact-canvas",
                  "title": "Business Impact Canvas",
                  "description": "Identify business, availability, security, data, compliance, and operational risks that should shape architecture and platform decisions.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 4,
                  "outcomes": [
                    "Documented business and operational impact assessment",
                    "Prioritized risks and mitigation actions",
                    "Evidence for architecture and platform decisions"
                  ],
                  "steps": [
                    "Availability Risks: Identify risks and impacts.",
                    "Ways to Mitigate Availability Risks: Define mitigation measures.",
                    "Security Risks: Document security-related risks.",
                    "Ways to Mitigate Security Risks: Propose strategies to mitigate security risks.",
                    "Data Risks: Identify risks to data accuracy or availability.",
                    "Ways to Mitigate Data Risks: Plan strategies to address data risks."
                  ],
                  "canvasId": "businessImpactCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "locationsCanvas",
                  "slug": "resources/location-canvas",
                  "title": "Location Canvas",
                  "description": "Map consumer, producer, system, data, network, regulatory, and trust-boundary locations to ensure compliance and performance across regions.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 6,
                  "outcomes": [
                    "Documented location, residency, network, and regulatory requirements",
                    "Regional performance and accessibility constraints identified",
                    "Data residency, trust boundaries, and applicable regulations clarified"
                  ],
                  "steps": [
                    "Map locations of producers, source systems, platforms, and consumers.",
                    "Document where consumers are located.",
                    "Identify applicable regulations.",
                    "Document where data must reside.",
                    "Ensure the capability is accessible in all intended network regions.",
                    "Validate network performance across regions."
                  ],
                  "canvasId": "locationsCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "capacityCanvas",
                  "slug": "resources/capacity-canvas",
                  "title": "Capacity Canvas",
                  "description": "Plan capacity for current and future demand, including volumes, peaks, latency, availability, scaling, caching, and rate limits for the selected capability and implementation style.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 7,
                  "outcomes": [
                    "Capacity requirements aligned with expected business demand",
                    "Peak-load, availability, and growth assumptions documented",
                    "Scaling, caching, and rate-limiting decisions defined"
                  ],
                  "steps": [
                    "Document current business volumes",
                    "Forecast future consumption trends",
                    "Plan for peak load and availability requirements",
                    "Define caching and rate-limiting strategies",
                    "Propose scaling strategies"
                  ],
                  "canvasId": "capacityCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "automation-operational-ownership-guide",
                  "slug": "resources/automation-operational-ownership-guide",
                  "title": "Automation Operational Ownership Guide",
                  "description": "Guidance for defining ownership, runbooks, supervision, support, monitoring, change control, and continuous improvement responsibilities for automations.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 185,
                  "outcomes": [
                    "Clear automation operating model",
                    "Ownership, support, and escalation responsibilities assigned",
                    "Monitoring and change practices ready for live operation"
                  ],
                  "steps": [
                    "Define business, technical, and operational owners for the automation.",
                    "Document runbooks, support paths, monitoring signals, service expectations, and escalation rules.",
                    "Set change control and review practices for workflow, platform, and rule updates."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                }
              ],
              "evidence": [
                "architecture-decision",
                "documentation",
                "platform-config",
                "metrics"
              ]
            },
            {
              "index": 4,
              "id": "api-design",
              "slug": "method/api-design",
              "icon": "api",
              "title": "Automation Workflow Design",
              "description": "Design the automation workflow, triggers, decision points, integrations, data handling, relevant interface contracts, and exception paths.",
              "whyItMatters": "Once the architecture pattern is known, the design must turn capability requirements into clear interface contracts, interactions, schemas, data rules, lifecycle expectations, and consumer obligations.",
              "applyInWork": "Select the design resources that fit the chosen implementation style and document the interface contract before implementation.",
              "outcomes": [
                "A validated interface contract for the selected implementation style",
                "Consistent interaction, data, event, file, workflow, or API contract decisions",
                "Design traceability back to capability and consumer requirements",
                "Designs aligned with domain models and interaction patterns"
              ],
              "steps": [
                {
                  "text": "Reuse the Domain Canvas to confirm business objects, terms, rules, and ownership before contract design.",
                  "resourceId": "domainCanvas",
                  "resourceTitle": "Domain Canvas",
                  "canvasId": "domainCanvas"
                },
                {
                  "text": "Use the Interaction Canvas to describe how consumers, systems, or users interact with the capability.",
                  "resourceId": "interactionCanvas",
                  "resourceTitle": "Interaction Canvas",
                  "canvasId": "interactionCanvas"
                },
                {
                  "text": "Use REST design resources when the selected interface is a REST API.",
                  "resourceId": "restCanvas",
                  "resourceTitle": "REST Canvas",
                  "canvasId": "restCanvas"
                },
                {
                  "text": "Use Event Canvas resources when the selected interface is event-driven.",
                  "resourceId": "eventCanvas",
                  "resourceTitle": "Event Canvas",
                  "canvasId": "eventCanvas"
                },
                {
                  "text": "Use GraphQL design resources when the selected interface is GraphQL.",
                  "resourceId": "graphqlCanvas",
                  "resourceTitle": "GraphQL Canvas",
                  "canvasId": "graphqlCanvas"
                },
                {
                  "text": "Use the design principles and style guidance to align design decisions with shared rules and enable consistent audit validation.",
                  "resourceId": "api-design-principles",
                  "resourceTitle": "API Design Principles",
                  "canvasId": null
                },
                {
                  "text": "Apply contract-first or design-first approaches to capture and validate the interface contract before implementation.",
                  "resourceId": "contract-first-design",
                  "resourceTitle": "Contract First Design",
                  "canvasId": null
                },
                {
                  "text": "Use the audit checklist to ensure the design meets functional and non-functional requirements, including security, performance, and compliance.",
                  "resourceId": "api-audit-checklist",
                  "resourceTitle": "API Audit Checklist",
                  "canvasId": null
                }
              ],
              "questions": [
                "Reuse the Domain Canvas to confirm business objects, terms, rules, and ownership before contract design.",
                "Use the Interaction Canvas to describe how consumers, systems, or users interact with the capability.",
                "Use REST design resources when the selected interface is a REST API.",
                "Use Event Canvas resources when the selected interface is event-driven.",
                "Use GraphQL design resources when the selected interface is GraphQL.",
                "Use the design principles and style guidance to align design decisions with shared rules and enable consistent audit validation.",
                "Apply contract-first or design-first approaches to capture and validate the interface contract before implementation.",
                "Use the audit checklist to ensure the design meets functional and non-functional requirements, including security, performance, and compliance.",
                "Select the design resources that fit the chosen implementation style and document the interface contract before implementation.",
                "Once the architecture pattern is known, the design must turn capability requirements into clear interface contracts, interactions, schemas, data rules, lifecycle expectations, and consumer obligations."
              ],
              "criteria": [
                "architecture-patterns-validated",
                "hide-backend-discrepancies",
                "design-reflects-business-value",
                "api-consistency"
              ],
              "criteriaDetails": [
                {
                  "id": "architecture-patterns-validated",
                  "title": "The chosen architecture, platform, and implementation style have been validated with the relevant architecture, security, and platform stakeholders.",
                  "description": "The chosen API architecture and platform patterns have been validated with the relevant architecture, security, and platform stakeholders."
                },
                {
                  "id": "hide-backend-discrepancies",
                  "title": "The selected interface provides an appropriate abstraction for consumers.",
                  "description": "The API is intended to shield consumers from backend complexity and inconsistencies."
                },
                {
                  "id": "design-reflects-business-value",
                  "title": "The interface design and exposed capabilities trace back to business value and consumer needs.",
                  "description": "The API design and exposed capabilities clearly trace back to business value and user needs."
                },
                {
                  "id": "api-consistency",
                  "title": "The interface design follows agreed design standards and conventions.",
                  "description": "The API design follows our shared API product and design conventions."
                }
              ],
              "baseTitle": "Solution & Interface Design",
              "group": "Capability Lifecycle Core Stations",
              "lifecycleStage": "design",
              "stakeholders": [
                {
                  "id": "automation-engineer",
                  "sourceKey": "automation-engineer",
                  "sourceStakeholderId": "automation-engineer",
                  "title": "Automation Engineer",
                  "description": "Implements, tests, integrates, and maintains automation solutions and supporting workflows.",
                  "involvement": "lead",
                  "responsibilities": []
                },
                {
                  "id": "automation-owner",
                  "sourceKey": "automation-owner",
                  "sourceStakeholderId": "automation-owner",
                  "title": "Automation Owner",
                  "description": "Owns automation goals, business value, priorities, controls, and lifecycle outcomes.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "domain-specialist",
                  "sourceKey": "domain-specialist",
                  "sourceStakeholderId": "domain-specialist",
                  "title": "Domain Expert",
                  "description": "Brings deep knowledge of the business domain, concepts, rules, and constraints the capability or interface must reflect.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "integration-architect",
                  "sourceKey": "integration-architect",
                  "sourceStakeholderId": "integration-architect",
                  "title": "Integration Architect",
                  "description": "Designs integration approaches and implementation styles that connect the capability or API with other systems.",
                  "involvement": "core",
                  "responsibilities": [
                    {
                      "resourceId": "interactionCanvas",
                      "resourceTitle": "Interaction Canvas",
                      "canvasId": "interactionCanvas",
                      "role": "suggested-answer-owner"
                    }
                  ]
                },
                {
                  "id": "process-owner",
                  "sourceKey": "process-owner",
                  "sourceStakeholderId": "process-owner",
                  "title": "Process Owner",
                  "description": "Owns the business process being automated, including objectives, rules, outcomes, and improvement priorities.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "api-designer",
                  "sourceKey": "api-designer",
                  "sourceStakeholderId": "api-designer",
                  "title": "API Designer",
                  "description": "Shapes the interface contract, interaction model, consistency, and usability of the exposed capabilities.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "compliance-specialist",
                  "sourceKey": "compliance-specialist",
                  "sourceStakeholderId": "compliance-specialist",
                  "title": "Compliance and Legal Specialist",
                  "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "security-specialist",
                  "sourceKey": "security-specialist",
                  "sourceStakeholderId": "security-specialist",
                  "title": "Security Specialist",
                  "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
                  "involvement": "consulted",
                  "responsibilities": []
                }
              ],
              "resources": [
                {
                  "id": "domainCanvas",
                  "slug": "resources/domain-canvas",
                  "title": "Domain Canvas",
                  "description": "A modeling tool to define and communicate the key entities and relationships in your domain, ensuring semantic consistency across capabilities, integrations, APIs, data products, and services.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 152,
                  "outcomes": [
                    "Shared domain model and terminology",
                    "Core entities, relationships, rules, and ownership clarified",
                    "Semantic consistency across capabilities, integrations, APIs, data products, and services"
                  ],
                  "steps": [
                    "Define core entities, their attributes, and relationships to create a shared conceptual understanding across capabilities, integrations, APIs, data products, and services."
                  ],
                  "canvasId": "domainCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "interactionCanvas",
                  "slug": "resources/interaction-canvas",
                  "title": "Interaction Canvas",
                  "description": "Define interactions, workflows, inputs, outputs, commands, queries, events, and expected responses to ensure a consistent consumer experience.",
                  "category": "canvas",
                  "icon": "dashboard-outline",
                  "order": 9,
                  "outcomes": [
                    "Defined interaction model for the selected capability",
                    "Inputs, outputs, commands, queries, events, and responses clarified",
                    "Validation rules and interaction expectations agreed"
                  ],
                  "steps": [
                    "Map interactions to user, consumer, or system tasks",
                    "Define access points, operations, commands, queries, or events for each interaction",
                    "Document inputs and outputs for each interaction.",
                    "Specify validation rules and constraints",
                    "Create interaction models for CRUD, query-driven, command-driven, and event-driven interactions"
                  ],
                  "canvasId": "interactionCanvas",
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": false
                },
                {
                  "id": "process-workflow-design-guide",
                  "slug": "resources/process-workflow-design-guide",
                  "title": "Process Workflow Design Guide",
                  "description": "Guidance for modeling the process steps, roles, handoffs, decision points, states, inputs, outputs, and exceptions that shape an automation workflow.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 181,
                  "outcomes": [
                    "Clear automation workflow design",
                    "Process steps and handoffs documented before implementation",
                    "Workflow states, inputs, outputs, and exception paths understood"
                  ],
                  "steps": [
                    "Map the current and target process flow, including human and system responsibilities.",
                    "Identify workflow triggers, states, decisions, data inputs, outputs, and completion criteria.",
                    "Document handoffs between users, systems, operations, and support roles.",
                    "Confirm which steps should be automated and which require human judgment."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                },
                {
                  "id": "decision-business-rules-guide",
                  "slug": "resources/decision-business-rules-guide",
                  "title": "Decision And Business Rules Guide",
                  "description": "Guidance for capturing rules, thresholds, decisions, approvals, eligibility checks, and rule ownership for automation design.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 182,
                  "outcomes": [
                    "Explicit decisions and business rules",
                    "Rules and thresholds documented with owners",
                    "Automation decisions traceable to policy, process, or business intent"
                  ],
                  "steps": [
                    "List decisions the automation must make or support.",
                    "Document rule conditions, thresholds, exceptions, approvals, and escalation points.",
                    "Identify rule owners and change governance for each decision area."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                },
                {
                  "id": "automation-trigger-handoff-exception-guide",
                  "slug": "resources/automation-trigger-handoff-exception-guide",
                  "title": "Automation Trigger, Handoff And Exception Guide",
                  "description": "Guidance for defining automation triggers, human handoffs, exception handling, retries, compensating actions, and support escalation paths.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 183,
                  "outcomes": [
                    "Defined automation triggers and exception paths",
                    "Human handoffs and support escalations are explicit",
                    "Exceptions, retries, and compensating actions are designed before delivery"
                  ],
                  "steps": [
                    "Define the events, schedules, user actions, or system states that trigger the automation.",
                    "Map handoffs from automation to users, operators, or support teams.",
                    "Document exceptions, retry rules, timeout behavior, and fallback paths.",
                    "Define alerts and escalation thresholds for failed or ambiguous automation outcomes."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                }
              ],
              "evidence": [
                "spec",
                "contract",
                "design-artifact",
                "documentation"
              ]
            },
            {
              "index": 5,
              "id": "api-delivery",
              "slug": "method/api-delivery",
              "icon": "code",
              "title": "Automation Delivery & Operations",
              "description": "Build, test, deploy, document, and operate the automation using clear ownership, controls, and rollback paths.",
              "whyItMatters": "A reusable capability needs reliable delivery and operations regardless of whether it becomes an API, event stream, file exchange, data product, or direct integration.",
              "applyInWork": "Apply delivery, testing, CI/CD, operations, and security guidance to the chosen implementation style.",
              "outcomes": [
                "A delivered capability aligned with the validated interface contract",
                "Automated testing, deployment, and environment controls",
                "Security, operations, and quality practices appropriate to the chosen pattern",
                "Traceable delivery and release controls"
              ],
              "steps": [
                {
                  "text": "Use development best practices to implement the validated interface contract with established frameworks, libraries, and team standards.",
                  "resourceId": "api-development-best-practices",
                  "resourceTitle": "API Development Best Practices",
                  "canvasId": null
                },
                {
                  "text": "Build the implementation from the validated interface contract using established frameworks, libraries, and team standards.",
                  "resourceId": "api-development-best-practices",
                  "resourceTitle": "API Development Best Practices",
                  "canvasId": null
                },
                {
                  "text": "Use testing guidance to verify functionality, data quality, compatibility, security, performance, resilience, and recovery expectations.",
                  "resourceId": "api-testing-best-practices",
                  "resourceTitle": "API Testing Best Practices",
                  "canvasId": null
                },
                {
                  "text": "Use CI/CD guidance to automate build, test, deployment, configuration, and traceability.",
                  "resourceId": "apiops-CI-CD-for-apis",
                  "resourceTitle": "APIOps CI/CD For APIs",
                  "canvasId": null
                },
                {
                  "text": "Use security guidance to protect data, access, credentials, and platform boundaries.",
                  "resourceId": "api-security-best-practices",
                  "resourceTitle": "API Security Best Practices",
                  "canvasId": null
                },
                {
                  "text": "Use the audit checklist to ensure the solution meets functional and non-functional requirements, including security, performance, and compliance.",
                  "resourceId": "api-audit-checklist",
                  "resourceTitle": "API Audit Checklist",
                  "canvasId": null
                }
              ],
              "questions": [
                "Use development best practices to implement the validated interface contract with established frameworks, libraries, and team standards.",
                "Build the implementation from the validated interface contract using established frameworks, libraries, and team standards.",
                "Use testing guidance to verify functionality, data quality, compatibility, security, performance, resilience, and recovery expectations.",
                "Use CI/CD guidance to automate build, test, deployment, configuration, and traceability.",
                "Use security guidance to protect data, access, credentials, and platform boundaries.",
                "Use the audit checklist to ensure the solution meets functional and non-functional requirements, including security, performance, and compliance.",
                "Apply delivery, testing, CI/CD, operations, and security guidance to the chosen implementation style.",
                "A reusable capability needs reliable delivery and operations regardless of whether it becomes an API, event stream, file exchange, data product, or direct integration."
              ],
              "criteria": [
                "architecture-patterns-validated",
                "hide-backend-discrepancies",
                "design-reflects-business-value",
                "api-consistency"
              ],
              "criteriaDetails": [
                {
                  "id": "architecture-patterns-validated",
                  "title": "The chosen architecture, platform, and implementation style have been validated with the relevant architecture, security, and platform stakeholders.",
                  "description": "The chosen API architecture and platform patterns have been validated with the relevant architecture, security, and platform stakeholders."
                },
                {
                  "id": "hide-backend-discrepancies",
                  "title": "The selected interface provides an appropriate abstraction for consumers.",
                  "description": "The API is intended to shield consumers from backend complexity and inconsistencies."
                },
                {
                  "id": "design-reflects-business-value",
                  "title": "The interface design and exposed capabilities trace back to business value and consumer needs.",
                  "description": "The API design and exposed capabilities clearly trace back to business value and user needs."
                },
                {
                  "id": "api-consistency",
                  "title": "The interface design follows agreed design standards and conventions.",
                  "description": "The API design follows our shared API product and design conventions."
                }
              ],
              "baseTitle": "Delivery & Operations",
              "group": "Capability Lifecycle Core Stations",
              "lifecycleStage": "delivery",
              "stakeholders": [
                {
                  "id": "automation-engineer",
                  "sourceKey": "automation-engineer",
                  "sourceStakeholderId": "automation-engineer",
                  "title": "Automation Engineer",
                  "description": "Implements, tests, integrates, and maintains automation solutions and supporting workflows.",
                  "involvement": "lead",
                  "responsibilities": []
                },
                {
                  "id": "automation-owner",
                  "sourceKey": "automation-owner",
                  "sourceStakeholderId": "automation-owner",
                  "title": "Automation Owner",
                  "description": "Owns automation goals, business value, priorities, controls, and lifecycle outcomes.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "platform-architect",
                  "sourceKey": "platform-architect",
                  "sourceStakeholderId": "platform-architect",
                  "title": "Platform Architect",
                  "description": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "security-specialist",
                  "sourceKey": "security-specialist",
                  "sourceStakeholderId": "security-specialist",
                  "title": "Security Specialist",
                  "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "operations-specialist",
                  "sourceKey": "operations-specialist",
                  "sourceStakeholderId": "operations-specialist",
                  "title": "Support and Operations Owner",
                  "description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "compliance-specialist",
                  "sourceKey": "compliance-specialist",
                  "sourceStakeholderId": "compliance-specialist",
                  "title": "Compliance and Legal Specialist",
                  "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "api-engineer",
                  "sourceKey": "api-engineer",
                  "sourceStakeholderId": "api-engineer",
                  "title": "Delivery Engineer",
                  "description": "Owns implementation, automation, testing, and release flow concerns needed to deliver the capability, API, or automation reliably.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "process-owner",
                  "sourceKey": "process-owner",
                  "sourceStakeholderId": "process-owner",
                  "title": "Process Owner",
                  "description": "Owns the business process being automated, including objectives, rules, outcomes, and improvement priorities.",
                  "involvement": "consulted",
                  "responsibilities": []
                }
              ],
              "resources": [
                {
                  "id": "automation-testing-guide",
                  "slug": "resources/automation-testing-guide",
                  "title": "Automation Testing Guide",
                  "description": "Guidance for testing automated workflows, decisions, integrations, exceptions, rollback behavior, supervision, and user impact before release.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 184,
                  "outcomes": [
                    "Validated automation behavior",
                    "Workflow, rule, exception, and integration tests defined",
                    "Release confidence for automated and human-assisted paths"
                  ],
                  "steps": [
                    "Create tests for happy paths, edge cases, exceptions, retries, and handoffs.",
                    "Validate business rules and decision outcomes with representative data.",
                    "Test rollback, recovery, observability, and manual intervention paths.",
                    "Include users and operators in acceptance testing where the automation changes work practices."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                },
                {
                  "id": "automation-operational-ownership-guide",
                  "slug": "resources/automation-operational-ownership-guide",
                  "title": "Automation Operational Ownership Guide",
                  "description": "Guidance for defining ownership, runbooks, supervision, support, monitoring, change control, and continuous improvement responsibilities for automations.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 185,
                  "outcomes": [
                    "Clear automation operating model",
                    "Ownership, support, and escalation responsibilities assigned",
                    "Monitoring and change practices ready for live operation"
                  ],
                  "steps": [
                    "Define business, technical, and operational owners for the automation.",
                    "Document runbooks, support paths, monitoring signals, service expectations, and escalation rules.",
                    "Set change control and review practices for workflow, platform, and rule updates."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                },
                {
                  "id": "automation-rollback-supervision-guide",
                  "slug": "resources/automation-rollback-supervision-guide",
                  "title": "Automation Rollback And Supervision Guide",
                  "description": "Guidance for designing rollback, pause, manual override, monitoring, supervision, and recovery paths for automations.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 186,
                  "outcomes": [
                    "Controlled automation recovery paths",
                    "Rollback, pause, and override behavior documented",
                    "Supervision needs and recovery responsibilities defined"
                  ],
                  "steps": [
                    "Identify actions that must be reversible, paused, or manually overridden.",
                    "Define rollback, compensation, and recovery procedures for failed or incorrect automation outcomes.",
                    "Document supervision thresholds, alerts, and manual decision points.",
                    "Validate recovery procedures before release."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                }
              ],
              "evidence": [
                "implementation",
                "pipeline-config",
                "test-report",
                "security-report"
              ]
            },
            {
              "index": 6,
              "id": "api-audit",
              "slug": "method/api-audit",
              "icon": "check-box-outline",
              "title": "Automation Readiness Review",
              "description": "Review automation readiness, quality, risk, compliance, human oversight, evidence, and release criteria.",
              "whyItMatters": "Reusable capabilities create operational, data, security, privacy, compliance, and consumer-impact risks. Readiness checks reduce surprises before release or production use.",
              "applyInWork": "Use audit and compliance resources to verify that the capability is ready for controlled release and reuse.",
              "outcomes": [
                "Documented readiness for release and reuse",
                "Known gaps and mitigations before release",
                "Evidence for governance, compliance, support, and operational approval",
                "Reduced risk of issues in production"
              ],
              "steps": [
                {
                  "text": "Use the audit checklist as a reusable quality checklist for interface contract, documentation, security, performance, and compliance readiness.",
                  "resourceId": "api-audit-checklist",
                  "resourceTitle": "API Audit Checklist",
                  "canvasId": null
                },
                {
                  "text": "Use checklists, linters, and testing tools to verify consistency and conformance with standards.",
                  "resourceId": "api-compliance-best-practices",
                  "resourceTitle": "API Compliance Best Practices",
                  "canvasId": null
                },
                {
                  "text": "Collaborate with governance teams and domain experts to ensure the capability is ready for production.",
                  "resourceTitle": "",
                  "canvasId": null
                }
              ],
              "questions": [
                "Use the audit checklist as a reusable quality checklist for interface contract, documentation, security, performance, and compliance readiness.",
                "Use checklists, linters, and testing tools to verify consistency and conformance with standards.",
                "Collaborate with governance teams and domain experts to ensure the capability is ready for production.",
                "Use audit and compliance resources to verify that the capability is ready for controlled release and reuse.",
                "Reusable capabilities create operational, data, security, privacy, compliance, and consumer-impact risks. Readiness checks reduce surprises before release or production use."
              ],
              "criteria": [
                "architecture-patterns-validated",
                "design-reflects-business-value",
                "api-description-available",
                "api-consistency",
                "api-contract-tested"
              ],
              "criteriaDetails": [
                {
                  "id": "architecture-patterns-validated",
                  "title": "The chosen architecture, platform, and implementation style have been validated with the relevant architecture, security, and platform stakeholders.",
                  "description": "The chosen API architecture and platform patterns have been validated with the relevant architecture, security, and platform stakeholders."
                },
                {
                  "id": "design-reflects-business-value",
                  "title": "The interface design and exposed capabilities trace back to business value and consumer needs.",
                  "description": "The API design and exposed capabilities clearly trace back to business value and user needs."
                },
                {
                  "id": "api-description-available",
                  "title": "The interface and its capabilities are documented clearly enough for review, audit, and onboarding.",
                  "description": "The API and its exposed capabilities are described clearly enough for review, audit, and onboarding."
                },
                {
                  "id": "api-consistency",
                  "title": "The interface design follows agreed design standards and conventions.",
                  "description": "The API design follows our shared API product and design conventions."
                },
                {
                  "id": "api-contract-tested",
                  "title": "The interface contract has been validated and tested against functional and non-functional requirements.",
                  "description": "The API contract is tested and meets functional and non-functional requirements."
                }
              ],
              "baseTitle": "Quality & Readiness Assurance",
              "group": "Capability Lifecycle Core Stations",
              "lifecycleStage": "publishing",
              "stakeholders": [
                {
                  "id": "governance-specialist",
                  "sourceKey": "governance-specialist",
                  "sourceStakeholderId": "governance-specialist",
                  "title": "API Governance Owner",
                  "description": "Represents review, audit, and organization-wide governance practices for API quality and conformity.",
                  "involvement": "lead",
                  "responsibilities": []
                },
                {
                  "id": "automation-owner",
                  "sourceKey": "automation-owner",
                  "sourceStakeholderId": "automation-owner",
                  "title": "Automation Owner",
                  "description": "Owns automation goals, business value, priorities, controls, and lifecycle outcomes.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "compliance-specialist",
                  "sourceKey": "compliance-specialist",
                  "sourceStakeholderId": "compliance-specialist",
                  "title": "Compliance and Legal Specialist",
                  "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "process-owner",
                  "sourceKey": "process-owner",
                  "sourceStakeholderId": "process-owner",
                  "title": "Process Owner",
                  "description": "Owns the business process being automated, including objectives, rules, outcomes, and improvement priorities.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "security-specialist",
                  "sourceKey": "security-specialist",
                  "sourceStakeholderId": "security-specialist",
                  "title": "Security Specialist",
                  "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "automation-engineer",
                  "sourceKey": "automation-engineer",
                  "sourceStakeholderId": "automation-engineer",
                  "title": "Automation Engineer",
                  "description": "Implements, tests, integrates, and maintains automation solutions and supporting workflows.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "platform-architect",
                  "sourceKey": "platform-architect",
                  "sourceStakeholderId": "platform-architect",
                  "title": "Platform Architect",
                  "description": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "operations-specialist",
                  "sourceKey": "operations-specialist",
                  "sourceStakeholderId": "operations-specialist",
                  "title": "Support and Operations Owner",
                  "description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
                  "involvement": "consulted",
                  "responsibilities": []
                }
              ],
              "resources": [
                {
                  "id": "automation-readiness-checklist",
                  "slug": "resources/automation-readiness-checklist",
                  "title": "Automation Readiness Checklist",
                  "description": "A checklist for validating automation workflow, controls, risk, compliance, human oversight, testing evidence, rollback, operations, and release readiness.",
                  "category": "checklist",
                  "icon": "check-box-outline",
                  "order": 187,
                  "outcomes": [
                    "Documented automation readiness",
                    "Known readiness gaps and mitigations before release",
                    "Evidence for quality, risk, compliance, oversight, and operational approval"
                  ],
                  "steps": [
                    "Review workflow design, business rules, controls, access, data handling, and exception paths.",
                    "Verify testing evidence, rollback procedures, supervision model, and support readiness.",
                    "Confirm ownership, runbooks, monitoring, change controls, and release approval.",
                    "Record unresolved gaps, decisions, and accepted risks before release."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                },
                {
                  "id": "api-compliance-best-practices",
                  "slug": "resources/api-compliance-best-practices",
                  "title": "API Compliance Best Practices",
                  "description": "Ensure APIs meet legal, regulatory, and internal compliance through documentation, controls, and automated validations.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 104,
                  "outcomes": [
                    "Shared understanding of the purpose and use of API Compliance Best Practices",
                    "A consistent approach to applying API Compliance Best Practices",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Document compliance measures and ensure they are communicated to stakeholders and consumers.",
                    "Implement measures to ensure APIs comply with these requirements, including data encryption, access controls, and audit trails.",
                    "Use checklists, linters, and testing tools to verify consistency and conformance with standards."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                }
              ],
              "evidence": [
                "audit-report",
                "compliance-report",
                "security-report",
                "test-report"
              ]
            },
            {
              "index": 7,
              "id": "api-publishing",
              "slug": "method/api-publishing",
              "icon": "deployed-code-outline",
              "title": "Automation Rollout & Enablement",
              "description": "Roll out the automation with discovery, onboarding, operating instructions, support paths, and change communication for users and operators.",
              "whyItMatters": "Reusable capabilities only create value when consumers can find them, understand their interface contract and service expectations, request access, and know who owns support and lifecycle decisions.",
              "applyInWork": "Publish ownership, documentation, onboarding, support contacts, service expectations, lifecycle status, and access request paths.",
              "outcomes": [
                "A discoverable reusable capability",
                "Clear onboarding, access, support, and service expectations",
                "Lifecycle and ownership information available to consumers and governance teams",
                "Consumers enabled to use and reuse the capability"
              ],
              "steps": [
                {
                  "text": "Publish capability information to the appropriate catalogs, portals, gateways, or environments to support reuse by multiple consumers.",
                  "resourceId": "apiops-CI-CD-for-apis",
                  "resourceTitle": "APIOps CI/CD For APIs",
                  "canvasId": null
                },
                {
                  "text": "Document how consumers find and use the capability, including onboarding processes and registration.",
                  "resourceId": "api-onboarding-best-practices",
                  "resourceTitle": "API Onboarding Best Practices",
                  "canvasId": null
                },
                {
                  "text": "Ensure security models, access configuration, and legal terms are clear and accessible to consumers.",
                  "resourceId": "api-audit-checklist",
                  "resourceTitle": "API Audit Checklist",
                  "canvasId": null
                }
              ],
              "questions": [
                "Publish capability information to the appropriate catalogs, portals, gateways, or environments to support reuse by multiple consumers.",
                "Document how consumers find and use the capability, including onboarding processes and registration.",
                "Ensure security models, access configuration, and legal terms are clear and accessible to consumers.",
                "Publish ownership, documentation, onboarding, support contacts, service expectations, lifecycle status, and access request paths.",
                "Reusable capabilities only create value when consumers can find them, understand their interface contract and service expectations, request access, and know who owns support and lifecycle decisions."
              ],
              "criteria": [
                "audit-passed",
                "audit-reports-shared",
                "api-ready-for-publishing",
                "api-documentation-ready"
              ],
              "criteriaDetails": [
                {
                  "id": "audit-passed",
                  "title": "The solution passes quality, security, compliance, and readiness checks.",
                  "description": "The API passes compliance, security, and audit checks."
                },
                {
                  "id": "audit-reports-shared",
                  "title": "Audit findings and remediation decisions are shared with the relevant stakeholders.",
                  "description": "Audit findings and remediation decisions are shared with the relevant stakeholders."
                },
                {
                  "id": "api-ready-for-publishing",
                  "title": "The capability is ready to be published or released through the selected delivery mechanism.",
                  "description": "The API is ready to be deployed and exposed through the intended gateways and environments."
                },
                {
                  "id": "api-documentation-ready",
                  "title": "Consumer-facing documentation and onboarding materials are ready.",
                  "description": "Consumer-facing API documentation is complete enough for publishing and onboarding."
                }
              ],
              "baseTitle": "Publishing & Enablement",
              "group": "Capability Lifecycle Core Stations",
              "lifecycleStage": "publishing",
              "stakeholders": [
                {
                  "id": "automation-owner",
                  "sourceKey": "automation-owner",
                  "sourceStakeholderId": "automation-owner",
                  "title": "Automation Owner",
                  "description": "Owns automation goals, business value, priorities, controls, and lifecycle outcomes.",
                  "involvement": "lead",
                  "responsibilities": []
                },
                {
                  "id": "api-devrel-specialist",
                  "sourceKey": "api-devrel-specialist",
                  "sourceStakeholderId": "api-devrel-specialist",
                  "title": "Documentation and DevRel Owner",
                  "description": "Owns onboarding content, developer communication, and documentation quality for API consumers.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "process-owner",
                  "sourceKey": "process-owner",
                  "sourceStakeholderId": "process-owner",
                  "title": "Process Owner",
                  "description": "Owns the business process being automated, including objectives, rules, outcomes, and improvement priorities.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "operations-specialist",
                  "sourceKey": "operations-specialist",
                  "sourceStakeholderId": "operations-specialist",
                  "title": "Support and Operations Owner",
                  "description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "automation-engineer",
                  "sourceKey": "automation-engineer",
                  "sourceStakeholderId": "automation-engineer",
                  "title": "Automation Engineer",
                  "description": "Implements, tests, integrates, and maintains automation solutions and supporting workflows.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "business-owner",
                  "sourceKey": "business-owner",
                  "sourceStakeholderId": "business-owner",
                  "title": "Business Owner",
                  "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "compliance-specialist",
                  "sourceKey": "compliance-specialist",
                  "sourceStakeholderId": "compliance-specialist",
                  "title": "Compliance and Legal Specialist",
                  "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
                  "involvement": "consulted",
                  "responsibilities": []
                }
              ],
              "resources": [
                {
                  "id": "automation-rollout-enablement-guide",
                  "slug": "resources/automation-rollout-enablement-guide",
                  "title": "Automation Rollout And Enablement Guide",
                  "description": "Guidance for rolling out automations with user communication, onboarding, operating instructions, support paths, change management, and feedback loops.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 188,
                  "outcomes": [
                    "Enabled automation users and operators",
                    "Rollout communication, onboarding, and support paths prepared",
                    "Users and operators understand how work changes after automation release"
                  ],
                  "steps": [
                    "Define rollout audiences, timing, communication channels, and training needs.",
                    "Publish operating instructions, support paths, exception handling guidance, and escalation contacts.",
                    "Plan transition support for users, operators, and process owners.",
                    "Collect feedback after rollout and feed improvements into the backlog."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                },
                {
                  "id": "service-agreement-template",
                  "slug": "resources/service-agreement-template",
                  "title": "Service Agreement Template",
                  "description": "A customizable agreement format that defines expectations, SLAs, responsibilities, and access terms for API consumption.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 172,
                  "outcomes": [
                    "Shared understanding of the purpose and use of Service Agreement Template",
                    "A consistent approach to applying Service Agreement Template",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Define service agreements that outline the expectations, service levels, and responsibilities for each API.",
                    "Use standardized formats to create machine-readable service agreements that are easy to share and validate.",
                    "Ensure service agreements are reviewed and approved by stakeholders to ensure alignment and clarity."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                }
              ],
              "evidence": [
                "gateway-config",
                "developer-portal",
                "documentation",
                "release-record"
              ]
            },
            {
              "index": 8,
              "id": "monitoring-and-improving",
              "slug": "method/monitoring-and-improving",
              "icon": "analytics-outline",
              "title": "Automation Monitoring & Improvement",
              "description": "Monitor automation performance, exceptions, reliability, user outcomes, operational impact, and improvement opportunities.",
              "whyItMatters": "Capabilities need continuous feedback to stay reliable, valuable, cost-effective, and reusable as consumers, systems, data, and platforms change.",
              "applyInWork": "Use metrics, analytics, and engagement practices to improve the capability over time.",
              "outcomes": [
                "Measured capability health and value",
                "Improvement backlog informed by operational and consumer feedback",
                "Reuse, reliability, data quality, and cost signals available to owners",
                "Continuous improvement aligned with consumer needs"
              ],
              "steps": [
                {
                  "text": "Use metrics and analytics guidance to define capability usage, reliability, data quality, cost, adoption, and consumer-value measures.",
                  "resourceId": "api-metrics-and-analytics",
                  "resourceTitle": "API Metrics And Analytics",
                  "canvasId": null
                },
                {
                  "text": "Analyze usage metrics and incorporate consumer feedback into capability iterations.",
                  "resourceId": "api-community-engagement-strategies",
                  "resourceTitle": "API Community Engagement Strategies",
                  "canvasId": null
                },
                {
                  "text": "Establish a habit of reviewing metrics and planning continuous improvement activities.",
                  "resourceId": "apiops-CI-CD-for-apis",
                  "resourceTitle": "APIOps CI/CD For APIs",
                  "canvasId": null
                }
              ],
              "questions": [
                "Use metrics and analytics guidance to define capability usage, reliability, data quality, cost, adoption, and consumer-value measures.",
                "Analyze usage metrics and incorporate consumer feedback into capability iterations.",
                "Establish a habit of reviewing metrics and planning continuous improvement activities.",
                "Use metrics, analytics, and engagement practices to improve the capability over time.",
                "Capabilities need continuous feedback to stay reliable, valuable, cost-effective, and reusable as consumers, systems, data, and platforms change."
              ],
              "criteria": [
                "api-documentation-ready",
                "consumer-support-ready",
                "legal-compliance-clear"
              ],
              "criteriaDetails": [
                {
                  "id": "api-documentation-ready",
                  "title": "Consumer-facing documentation and onboarding materials are ready.",
                  "description": "Consumer-facing API documentation is complete enough for publishing and onboarding."
                },
                {
                  "id": "consumer-support-ready",
                  "title": "Consumer onboarding, support, and communication processes are ready.",
                  "description": "Registration, support, and communication processes are ready for API consumers."
                },
                {
                  "id": "legal-compliance-clear",
                  "title": "Legal, privacy, and compliance requirements for publishing or release are defined and understood.",
                  "description": "Legal, privacy, and compliance requirements for publishing are defined and understood."
                }
              ],
              "baseTitle": "Monitoring & Improvement",
              "group": "Capability Lifecycle Core Stations",
              "lifecycleStage": "improving",
              "stakeholders": [
                {
                  "id": "automation-owner",
                  "sourceKey": "automation-owner",
                  "sourceStakeholderId": "automation-owner",
                  "title": "Automation Owner",
                  "description": "Owns automation goals, business value, priorities, controls, and lifecycle outcomes.",
                  "involvement": "lead",
                  "responsibilities": []
                },
                {
                  "id": "automation-engineer",
                  "sourceKey": "automation-engineer",
                  "sourceStakeholderId": "automation-engineer",
                  "title": "Automation Engineer",
                  "description": "Implements, tests, integrates, and maintains automation solutions and supporting workflows.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "process-owner",
                  "sourceKey": "process-owner",
                  "sourceStakeholderId": "process-owner",
                  "title": "Process Owner",
                  "description": "Owns the business process being automated, including objectives, rules, outcomes, and improvement priorities.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "operations-specialist",
                  "sourceKey": "operations-specialist",
                  "sourceStakeholderId": "operations-specialist",
                  "title": "Support and Operations Owner",
                  "description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
                  "involvement": "core",
                  "responsibilities": []
                },
                {
                  "id": "business-owner",
                  "sourceKey": "business-owner",
                  "sourceStakeholderId": "business-owner",
                  "title": "Business Owner",
                  "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "compliance-specialist",
                  "sourceKey": "compliance-specialist",
                  "sourceStakeholderId": "compliance-specialist",
                  "title": "Compliance and Legal Specialist",
                  "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "platform-owner",
                  "sourceKey": "platform-owner",
                  "sourceStakeholderId": "platform-owner",
                  "title": "Platform Owner",
                  "description": "Owns platform capabilities, roadmap, operational model, and service expectations.",
                  "involvement": "consulted",
                  "responsibilities": []
                },
                {
                  "id": "security-specialist",
                  "sourceKey": "security-specialist",
                  "sourceStakeholderId": "security-specialist",
                  "title": "Security Specialist",
                  "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
                  "involvement": "consulted",
                  "responsibilities": []
                }
              ],
              "resources": [
                {
                  "id": "automation-operational-ownership-guide",
                  "slug": "resources/automation-operational-ownership-guide",
                  "title": "Automation Operational Ownership Guide",
                  "description": "Guidance for defining ownership, runbooks, supervision, support, monitoring, change control, and continuous improvement responsibilities for automations.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 185,
                  "outcomes": [
                    "Clear automation operating model",
                    "Ownership, support, and escalation responsibilities assigned",
                    "Monitoring and change practices ready for live operation"
                  ],
                  "steps": [
                    "Define business, technical, and operational owners for the automation.",
                    "Document runbooks, support paths, monitoring signals, service expectations, and escalation rules.",
                    "Set change control and review practices for workflow, platform, and rule updates."
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                },
                {
                  "id": "api-metrics-and-analytics",
                  "slug": "resources/api-metrics-and-analytics",
                  "title": "API Metrics And Analytics",
                  "description": "A resource for defining, collecting, and analyzing API performance and usage data to align technical KPIs with business outcomes.",
                  "category": "guideline",
                  "icon": "edit-document-outline",
                  "order": 119,
                  "outcomes": [
                    "Shared understanding of the purpose and use of API Metrics And Analytics",
                    "A consistent approach to applying API Metrics And Analytics",
                    "Improved application of the related practices"
                  ],
                  "steps": [
                    "Identify key performance indicators (KPIs) to measure API success against business goals.",
                    "Define and monitor performance metrics (e.g., API calls, latency, error rates) and adoption metrics (e.g., NPS).",
                    "Monitor API initiatives to ensure adherence to operating guidelines and governance practices"
                  ],
                  "canvasId": null,
                  "sourcePath": null,
                  "sourceUrl": null,
                  "contentMarkdown": null,
                  "draft": true
                }
              ],
              "evidence": [
                "metrics",
                "consumer-feedback",
                "incident-report",
                "roadmap"
              ]
            }
          ]
        }
      ],
      "lines": [
        {
          "id": "business-opportunities-line",
          "slug": "business-opportunities-line",
          "title": "Business Opportunities Line",
          "description": "Focuses on identifying and shaping business opportunities as reusable digital capabilities.",
          "icon": "",
          "color": "#26b309",
          "order": 1,
          "stations": [
            "monitoring-and-improving",
            "api-product-strategy",
            "user-experience",
            "market-insights",
            "business-goals",
            "competitive-analysis",
            "ecosystem-vision"
          ]
        },
        {
          "id": "platform-architecture-line",
          "slug": "platform-architecture-line",
          "title": "Platform Architecture Line",
          "description": "Covers architecture and platform decisions for reusable capabilities across implementation styles.",
          "icon": "",
          "color": "#933469",
          "order": 2,
          "stations": [
            "api-product-strategy",
            "api-consumer-experience",
            "api-platform-architecture",
            "scalable-infrastructure",
            "legal-and-compliance",
            "security-and-privacy",
            "design-standards",
            "vendor-management"
          ]
        },
        {
          "id": "api-design-line",
          "slug": "api-design-line",
          "title": "Design Line",
          "description": "Focuses on solution and interface design principles that can be used across APIs, integrations, automations, data products, and other implementation styles.",
          "icon": "",
          "color": "#db9b0c",
          "order": 3,
          "stations": [
            "api-platform-architecture",
            "api-design",
            "api-delivery",
            "api-audit"
          ]
        },
        {
          "id": "delivery-line",
          "slug": "delivery-line",
          "title": "Delivery Line",
          "description": "Covers delivery and operational practices for reusable capabilities across implementation styles.",
          "icon": "",
          "color": "#db9b0c",
          "order": 4,
          "stations": [
            "api-delivery",
            "contract-design",
            "development",
            "ci-cd",
            "test-automation",
            "release-management"
          ]
        },
        {
          "id": "publishing-and-adoption-line",
          "slug": "publishing-and-adoption-line",
          "title": "Publishing and Adoption Line",
          "description": "Focuses on publishing reusable capabilities and enabling adoption by consumers.",
          "icon": "",
          "color": "#17C6E9",
          "order": 5,
          "stations": [
            "api-audit",
            "api-publishing",
            "monitoring-and-improving",
            "service-agreements",
            "api-consumer-adoption",
            "api-promotion",
            "partner-integration"
          ]
        },
        {
          "id": "operating-model-line",
          "slug": "operating-model-line",
          "title": "Operating Model Line",
          "description": "Covers the operating model for reusable capability management and governance.",
          "icon": "",
          "color": "#1a3987",
          "order": 6,
          "stations": [
            "api-product-strategy",
            "api-mindset",
            "roles-and-responsibilities",
            "upskilling",
            "operating-guidelines",
            "portfolio-management",
            "budget-and-resource-management"
          ]
        }
      ],
      "stations": [
        {
          "id": "api-product-strategy",
          "slug": "method/api-product-strategy",
          "icon": "strategy-outline",
          "title": "Strategy",
          "description": "Frame the business need as a reusable capability before choosing the implementation style.",
          "whyItMatters": "Integration and API work often jumps too quickly to a technical pattern. This station keeps the team focused on the business journey, domain meaning, value, reuse potential, ownership, and viability before selecting APIs, events, files, streams, data products, or direct integration.",
          "applyInWork": "Use shared journey, domain, value proposition, and business model canvases to gather technology-agnostic requirements and decide whether the capability should be reusable.",
          "group": "Capability Lifecycle Core Stations",
          "lifecycleStage": "strategy",
          "outcomes": [
            "A technology-agnostic capability opportunity statement",
            "Shared understanding of consumers, producers, domain concepts, and reuse potential",
            "A capability value proposition and business model before architecture selection"
          ],
          "steps": [
            {
              "text": "Map the customer or partner journey that creates the capability need and reveals tasks, pains, gains, inputs, outputs, and decision points.",
              "resourceId": "customerJourneyCanvas",
              "resourceTitle": "Customer Journey Canvas",
              "canvasId": "customerJourneyCanvas"
            },
            {
              "text": "Define the core entities, attributes, relationships, ownership, and business rules that the capability must respect.",
              "resourceId": "domainCanvas",
              "resourceTitle": "Domain Canvas",
              "canvasId": "domainCanvas"
            },
            {
              "text": "Use the Capability Value Proposition Canvas to capture consumer tasks, gains, pains, and reusable capability features without naming the delivery technology too early.",
              "resourceId": "apiValuePropositionCanvas",
              "resourceTitle": "API Value Proposition Canvas",
              "canvasId": "apiValuePropositionCanvas"
            },
            {
              "text": "Use the Capability Business Model Canvas to clarify ownership, partners, channels, costs, benefits, support, and lifecycle expectations for the reusable capability.",
              "resourceId": "apiBusinessModelCanvas",
              "resourceTitle": "API Business Model Canvas",
              "canvasId": "apiBusinessModelCanvas"
            }
          ],
          "questions": [
            "Map the customer or partner journey that creates the capability need and reveals tasks, pains, gains, inputs, outputs, and decision points.",
            "Define the core entities, attributes, relationships, ownership, and business rules that the capability must respect.",
            "Use the Capability Value Proposition Canvas to capture consumer tasks, gains, pains, and reusable capability features without naming the delivery technology too early.",
            "Use the Capability Business Model Canvas to clarify ownership, partners, channels, costs, benefits, support, and lifecycle expectations for the reusable capability.",
            "Use shared journey, domain, value proposition, and business model canvases to gather technology-agnostic requirements and decide whether the capability should be reusable.",
            "Integration and API work often jumps too quickly to a technical pattern. This station keeps the team focused on the business journey, domain meaning, value, reuse potential, ownership, and viability before selecting APIs, events, files, streams, data products, or direct integration."
          ],
          "criteria": [
            "metrics-feedback-available",
            "business-goals-defined",
            "market-research-done",
            "stakeholder-approval"
          ],
          "criteriaDetails": [
            {
              "id": "metrics-feedback-available",
              "title": "Relevant market signals, feedback, or operational insights are available to guide this capability opportunity.",
              "description": "Relevant market signals, feedback, or operational insights are available to guide this API opportunity."
            },
            {
              "id": "business-goals-defined",
              "title": "Business goals are defined.",
              "description": "Business goals are defined."
            },
            {
              "id": "market-research-done",
              "title": "Market research identifies capability opportunities.",
              "description": "Market research identifies API opportunities."
            },
            {
              "id": "stakeholder-approval",
              "title": "Relevant stakeholders agree this capability opportunity is worth exploring and prioritizing.",
              "description": "Relevant stakeholders agree this API opportunity is worth exploring and prioritizing."
            }
          ],
          "stakeholders": [
            {
              "id": "api-product-owner",
              "sourceKey": "api-product-owner",
              "sourceStakeholderId": "api-product-owner",
              "title": "API Product Owner",
              "description": "Drives the API opportunity, prioritization, and product-level decisions across the lifecycle.",
              "involvement": "lead",
              "responsibilities": [
                {
                  "resourceId": "apiValuePropositionCanvas",
                  "resourceTitle": "API Value Proposition Canvas",
                  "canvasId": "apiValuePropositionCanvas",
                  "role": "suggested-answer-owner"
                },
                {
                  "resourceId": "apiBusinessModelCanvas",
                  "resourceTitle": "API Business Model Canvas",
                  "canvasId": "apiBusinessModelCanvas",
                  "role": "suggested-answer-owner"
                }
              ]
            },
            {
              "id": "automation-owner",
              "sourceKey": "automation-owner",
              "sourceStakeholderId": "automation-owner",
              "title": "Automation Owner",
              "description": "Owns automation goals, business value, priorities, controls, and lifecycle outcomes.",
              "involvement": "lead",
              "responsibilities": []
            },
            {
              "id": "capability-owner",
              "sourceKey": "capability-owner",
              "sourceStakeholderId": "capability-owner",
              "title": "Capability Owner",
              "description": "Owns the capability vision, value, priorities, lifecycle, and reuse across consumers.",
              "involvement": "lead",
              "responsibilities": [
                {
                  "resourceId": "capabilityValuePropositionCanvas",
                  "resourceTitle": "Capability Value Proposition Canvas",
                  "canvasId": "capabilityValuePropositionCanvas",
                  "role": "suggested-answer-owner"
                },
                {
                  "resourceId": "capabilityBusinessModelCanvas",
                  "resourceTitle": "Capability Business Model Canvas",
                  "canvasId": "capabilityBusinessModelCanvas",
                  "role": "suggested-answer-owner"
                }
              ]
            },
            {
              "id": "integration-architect",
              "sourceKey": "integration-architect",
              "sourceStakeholderId": "integration-architect",
              "title": "Integration Architect",
              "description": "Designs integration approaches and implementation styles that connect the capability or API with other systems.",
              "involvement": "lead",
              "responsibilities": []
            },
            {
              "id": "business-owner",
              "sourceKey": "business-owner",
              "sourceStakeholderId": "business-owner",
              "title": "Business Owner",
              "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
              "involvement": "core",
              "responsibilities": [
                {
                  "resourceId": "customerJourneyCanvas",
                  "resourceTitle": "Customer Journey Canvas",
                  "canvasId": "customerJourneyCanvas",
                  "role": "suggested-answer-owner"
                }
              ]
            },
            {
              "id": "customer-specialist",
              "sourceKey": "customer-specialist",
              "sourceStakeholderId": "customer-specialist",
              "title": "Customer or Partner Representative",
              "description": "Contributes the business customer or partner perspective for the journey, value, and collaboration model.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "domain-specialist",
              "sourceKey": "domain-specialist",
              "sourceStakeholderId": "domain-specialist",
              "title": "Domain Expert",
              "description": "Brings deep knowledge of the business domain, concepts, rules, and constraints the capability or interface must reflect.",
              "involvement": "core",
              "responsibilities": [
                {
                  "resourceId": "domainCanvas",
                  "resourceTitle": "Domain Canvas",
                  "canvasId": "domainCanvas",
                  "role": "suggested-answer-owner"
                }
              ]
            },
            {
              "id": "platform-owner",
              "sourceKey": "platform-owner",
              "sourceStakeholderId": "platform-owner",
              "title": "Platform Owner",
              "description": "Owns platform capabilities, roadmap, operational model, and service expectations.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "process-owner",
              "sourceKey": "process-owner",
              "sourceStakeholderId": "process-owner",
              "title": "Process Owner",
              "description": "Owns the business process being automated, including objectives, rules, outcomes, and improvement priorities.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "api-consumer-specialist",
              "sourceKey": "api-consumer-specialist",
              "sourceStakeholderId": "api-consumer-specialist",
              "title": "API Consumer Representative",
              "description": "Represents the needs of developers, integrators, or other API consumers who use the API directly.",
              "involvement": "consulted",
              "responsibilities": []
            },
            {
              "id": "api-program-owner",
              "sourceKey": "api-program-owner",
              "sourceStakeholderId": "api-program-owner",
              "title": "API Program Owner",
              "description": "Coordinates API portfolio practices, organizational alignment, and long-term API capability development.",
              "involvement": "consulted",
              "responsibilities": []
            },
            {
              "id": "automation-engineer",
              "sourceKey": "automation-engineer",
              "sourceStakeholderId": "automation-engineer",
              "title": "Automation Engineer",
              "description": "Implements, tests, integrates, and maintains automation solutions and supporting workflows.",
              "involvement": "consulted",
              "responsibilities": []
            },
            {
              "id": "compliance-specialist",
              "sourceKey": "compliance-specialist",
              "sourceStakeholderId": "compliance-specialist",
              "title": "Compliance and Legal Specialist",
              "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
              "involvement": "consulted",
              "responsibilities": []
            },
            {
              "id": "partner-specialist",
              "sourceKey": "partner-specialist",
              "sourceStakeholderId": "partner-specialist",
              "title": "Partner or Vendor Manager",
              "description": "Coordinates external partner, supplier, or vendor relationships that influence capability or API strategy and delivery.",
              "involvement": "consulted",
              "responsibilities": []
            },
            {
              "id": "platform-architect",
              "sourceKey": "platform-architect",
              "sourceStakeholderId": "platform-architect",
              "title": "Platform Architect",
              "description": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
              "involvement": "consulted",
              "responsibilities": []
            },
            {
              "id": "security-specialist",
              "sourceKey": "security-specialist",
              "sourceStakeholderId": "security-specialist",
              "title": "Security Specialist",
              "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
              "involvement": "consulted",
              "responsibilities": []
            }
          ],
          "evidence": [
            "design-artifact",
            "documentation",
            "research",
            "roadmap"
          ]
        },
        {
          "id": "user-experience",
          "slug": "method/user-experience",
          "icon": "user-attributes-outline",
          "title": "User Experience - Design APIs with the User in Mind",
          "description": "Ensure APIs are designed with the end user in mind, providing a seamless and intuitive experience.",
          "whyItMatters": "APIs are not just technical products; they are user-facing products. A poor user experience can lead to low adoption and frustration. This station helps teams design APIs that are user-friendly and meet consumer needs.",
          "applyInWork": "Provide user experience guidelines, templates, and tools for API design. Ensure teams follow user-centered design practices and incorporate user feedback into API iterations.",
          "group": "Supporting Stations",
          "lifecycleStage": "supporting",
          "outcomes": [
            "APIs designed with user needs in mind",
            "Intuitive and consistent user interfaces",
            "User feedback incorporated into API design",
            "Improved user satisfaction and adoption"
          ],
          "steps": [
            {
              "text": "Use user personas to understand the needs and expectations of end-users",
              "resourceId": "customerJourneyCanvas",
              "resourceTitle": "Customer Journey Canvas",
              "canvasId": "customerJourneyCanvas"
            },
            {
              "text": "Conduct user research to gather insights on how consumers interact with the ecosystem services or your API consuming applications.",
              "resourceId": "customerJourneyCanvas",
              "resourceTitle": "Customer Journey Canvas",
              "canvasId": "customerJourneyCanvas"
            },
            {
              "text": "Document the user experience requirements so that they can be used in API design, ensuring they are intuitive and easy to use.",
              "resourceId": "customerJourneyCanvas",
              "resourceTitle": "Customer Journey Canvas",
              "canvasId": "customerJourneyCanvas"
            }
          ],
          "questions": [
            "Use user personas to understand the needs and expectations of end-users",
            "Conduct user research to gather insights on how consumers interact with the ecosystem services or your API consuming applications.",
            "Document the user experience requirements so that they can be used in API design, ensuring they are intuitive and easy to use.",
            "Provide user experience guidelines, templates, and tools for API design. Ensure teams follow user-centered design practices and incorporate user feedback into API iterations.",
            "APIs are not just technical products; they are user-facing products. A poor user experience can lead to low adoption and frustration. This station helps teams design APIs that are user-friendly and meet consumer needs."
          ],
          "criteria": [],
          "criteriaDetails": [],
          "stakeholders": [],
          "evidence": []
        },
        {
          "id": "api-consumer-experience",
          "slug": "method/api-consumer-experience",
          "icon": "deployed-code-account-outline",
          "title": "Consumer Requirements & Onboarding",
          "description": "Capture consumer onboarding, standards, non-functional requirements, service expectations, constraints, security needs, allowed protocols, data freshness, SLAs, observability, recovery, adoption requirements, and producer responsibilities.",
          "whyItMatters": "The right architecture depends on consumer goals, onboarding expectations, service levels, data quality needs, change tolerance, observability, support, and producer constraints.",
          "applyInWork": "Use consumer experience and onboarding guidance to make expectations explicit for both consumers and producers.",
          "group": "Capability Lifecycle Core Stations",
          "lifecycleStage": "strategy",
          "outcomes": [
            "Documented consumer requirements and onboarding expectations",
            "Clear producer responsibilities and support expectations",
            "Architecture-relevant constraints ready for decision making",
            "Improved adoption through consumer empathy, standards, and producer clarity"
          ],
          "steps": [
            {
              "text": "Use the Consumer Experience Requirements Canvas to capture consumer goals, availability, freshness, volume, performance, data quality, security, onboarding, change, observability, and recovery expectations.",
              "resourceId": "apiValuePropositionCanvas",
              "resourceTitle": "API Value Proposition Canvas",
              "canvasId": "apiValuePropositionCanvas"
            },
            {
              "text": "Use onboarding guidance to describe how consumers will find, request, test, get approved for, and start using the capability.",
              "resourceId": "customerJourneyCanvas",
              "resourceTitle": "Customer Journey Canvas",
              "canvasId": "customerJourneyCanvas"
            },
            {
              "text": "Use the resulting journey and requirements to improve onboarding, documentation, support, and feedback loops for capability consumers.",
              "resourceId": "api-onboarding-best-practices",
              "resourceTitle": "API Onboarding Best Practices",
              "canvasId": null
            }
          ],
          "questions": [
            "Use the Consumer Experience Requirements Canvas to capture consumer goals, availability, freshness, volume, performance, data quality, security, onboarding, change, observability, and recovery expectations.",
            "Use onboarding guidance to describe how consumers will find, request, test, get approved for, and start using the capability.",
            "Use the resulting journey and requirements to improve onboarding, documentation, support, and feedback loops for capability consumers.",
            "Use consumer experience and onboarding guidance to make expectations explicit for both consumers and producers.",
            "The right architecture depends on consumer goals, onboarding expectations, service levels, data quality needs, change tolerance, observability, support, and producer constraints."
          ],
          "criteria": [
            "api-opportunity-documented",
            "api-reusability",
            "hide-backend-discrepancies",
            "value-prop-validated",
            "consumer-segments-identified",
            "api-roadmap-defined"
          ],
          "criteriaDetails": [
            {
              "id": "api-opportunity-documented",
              "title": "Capability opportunity is identified and documented.",
              "description": "Individual API opportunities are identified and documented."
            },
            {
              "id": "api-reusability",
              "title": "The capability addresses a clear business need and is reusable by its intended consumers.",
              "description": "The API meets a clear business need and is reusable for multiple API consumers."
            },
            {
              "id": "hide-backend-discrepancies",
              "title": "The selected interface provides an appropriate abstraction for consumers.",
              "description": "The API is intended to shield consumers from backend complexity and inconsistencies."
            },
            {
              "id": "value-prop-validated",
              "title": "The capability value proposition has been validated with business and consumer stakeholders.",
              "description": "The API value proposition has been reviewed and validated with the relevant business and consumer stakeholders."
            },
            {
              "id": "consumer-segments-identified",
              "title": "Consumer segments are identified.",
              "description": "API consumer segments (internal and external) are identified."
            },
            {
              "id": "api-roadmap-defined",
              "title": "A high-level implementation roadmap is defined.",
              "description": "High-level roadmaps for API development are established."
            }
          ],
          "stakeholders": [
            {
              "id": "api-consumer-specialist",
              "sourceKey": "api-consumer-specialist",
              "sourceStakeholderId": "api-consumer-specialist",
              "title": "API Consumer Representative",
              "description": "Represents the needs of developers, integrators, or other API consumers who use the API directly.",
              "involvement": "lead",
              "responsibilities": [
                {
                  "resourceId": "consumerExperienceRequirementsCanvas",
                  "resourceTitle": "Consumer Experience Requirements Canvas",
                  "canvasId": "consumerExperienceRequirementsCanvas",
                  "role": "suggested-answer-owner"
                }
              ]
            },
            {
              "id": "api-product-owner",
              "sourceKey": "api-product-owner",
              "sourceStakeholderId": "api-product-owner",
              "title": "API Product Owner",
              "description": "Drives the API opportunity, prioritization, and product-level decisions across the lifecycle.",
              "involvement": "lead",
              "responsibilities": []
            },
            {
              "id": "customer-specialist",
              "sourceKey": "customer-specialist",
              "sourceStakeholderId": "customer-specialist",
              "title": "Customer or Partner Representative",
              "description": "Contributes the business customer or partner perspective for the journey, value, and collaboration model.",
              "involvement": "lead",
              "responsibilities": []
            },
            {
              "id": "process-owner",
              "sourceKey": "process-owner",
              "sourceStakeholderId": "process-owner",
              "title": "Process Owner",
              "description": "Owns the business process being automated, including objectives, rules, outcomes, and improvement priorities.",
              "involvement": "lead",
              "responsibilities": []
            },
            {
              "id": "automation-owner",
              "sourceKey": "automation-owner",
              "sourceStakeholderId": "automation-owner",
              "title": "Automation Owner",
              "description": "Owns automation goals, business value, priorities, controls, and lifecycle outcomes.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "capability-owner",
              "sourceKey": "capability-owner",
              "sourceStakeholderId": "capability-owner",
              "title": "Capability Owner",
              "description": "Owns the capability vision, value, priorities, lifecycle, and reuse across consumers.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "api-devrel-specialist",
              "sourceKey": "api-devrel-specialist",
              "sourceStakeholderId": "api-devrel-specialist",
              "title": "Documentation and DevRel Owner",
              "description": "Owns onboarding content, developer communication, and documentation quality for API consumers.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "domain-specialist",
              "sourceKey": "domain-specialist",
              "sourceStakeholderId": "domain-specialist",
              "title": "Domain Expert",
              "description": "Brings deep knowledge of the business domain, concepts, rules, and constraints the capability or interface must reflect.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "integration-architect",
              "sourceKey": "integration-architect",
              "sourceStakeholderId": "integration-architect",
              "title": "Integration Architect",
              "description": "Designs integration approaches and implementation styles that connect the capability or API with other systems.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "api-designer",
              "sourceKey": "api-designer",
              "sourceStakeholderId": "api-designer",
              "title": "API Designer",
              "description": "Shapes the interface contract, interaction model, consistency, and usability of the exposed capabilities.",
              "involvement": "consulted",
              "responsibilities": []
            },
            {
              "id": "business-owner",
              "sourceKey": "business-owner",
              "sourceStakeholderId": "business-owner",
              "title": "Business Owner",
              "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
              "involvement": "consulted",
              "responsibilities": []
            },
            {
              "id": "compliance-specialist",
              "sourceKey": "compliance-specialist",
              "sourceStakeholderId": "compliance-specialist",
              "title": "Compliance and Legal Specialist",
              "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
              "involvement": "consulted",
              "responsibilities": []
            },
            {
              "id": "partner-specialist",
              "sourceKey": "partner-specialist",
              "sourceStakeholderId": "partner-specialist",
              "title": "Partner or Vendor Manager",
              "description": "Coordinates external partner, supplier, or vendor relationships that influence capability or API strategy and delivery.",
              "involvement": "consulted",
              "responsibilities": []
            },
            {
              "id": "operations-specialist",
              "sourceKey": "operations-specialist",
              "sourceStakeholderId": "operations-specialist",
              "title": "Support and Operations Owner",
              "description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
              "involvement": "consulted",
              "responsibilities": []
            }
          ],
          "evidence": [
            "design-artifact",
            "documentation",
            "consumer-feedback"
          ]
        },
        {
          "id": "market-insights",
          "slug": "method/market-insights",
          "icon": "area-chart-outline",
          "title": "Market Insights - Understand the API Landscape",
          "description": "Analyze market trends, competitor APIs, and industry standards to inform API strategy.",
          "whyItMatters": "Understanding the market landscape helps teams identify opportunities, avoid pitfalls, and align their APIs with industry standards. This station provides tools to analyze market trends and competitor offerings.",
          "applyInWork": "Provide market research tools, competitor analysis templates, and industry standards resources. Ensure teams stay informed about market trends and incorporate insights into API strategy.",
          "group": "Supporting Stations",
          "lifecycleStage": "supporting",
          "outcomes": [
            "Market trends and competitor APIs analyzed",
            "Industry standards and best practices identified",
            "API strategy aligned with market needs",
            "Informed decision-making based on market insights"
          ],
          "steps": [
            {
              "text": "Conduct market research to identify trends, opportunities, and threats in the API landscape.",
              "resourceId": "ecosystem-vision-template",
              "resourceTitle": "Ecosystem Vision Template",
              "canvasId": null
            },
            {
              "text": "Analyze competitor APIs to understand their strengths, weaknesses, and unique selling points.",
              "resourceId": "competitor-analysis-template",
              "resourceTitle": "Competitor Analysis Template",
              "canvasId": null
            },
            {
              "text": "Identify industry standards and best practices to ensure APIs are competitive and compliant.",
              "resourceId": "industry-standards-and-best-practices",
              "resourceTitle": "Industry Standards And Best Practices",
              "canvasId": null
            }
          ],
          "questions": [
            "Conduct market research to identify trends, opportunities, and threats in the API landscape.",
            "Analyze competitor APIs to understand their strengths, weaknesses, and unique selling points.",
            "Identify industry standards and best practices to ensure APIs are competitive and compliant.",
            "Provide market research tools, competitor analysis templates, and industry standards resources. Ensure teams stay informed about market trends and incorporate insights into API strategy.",
            "Understanding the market landscape helps teams identify opportunities, avoid pitfalls, and align their APIs with industry standards. This station provides tools to analyze market trends and competitor offerings."
          ],
          "criteria": [],
          "criteriaDetails": [],
          "stakeholders": [],
          "evidence": []
        },
        {
          "id": "api-platform-architecture",
          "slug": "method/api-platform-architecture",
          "icon": "code-blocks-outline",
          "title": "Architecture & Platform Decisions",
          "description": "Use requirements and constraints to decide the right architecture pattern and enabling platform capabilities.",
          "whyItMatters": "Architecture choices should follow from evidence about business impact, locations, trust boundaries, capacity, latency, data ownership, consistency, operability, security, privacy, governance, and cost.",
          "applyInWork": "Compare viable architecture styles against the gathered requirements and document the selected pattern and rationale.",
          "group": "Capability Lifecycle Core Stations",
          "lifecycleStage": "architecture",
          "outcomes": [
            "A justified architecture choice",
            "Documented risks, locations, capacity, security, privacy, and operability constraints",
            "Clear rationale for API, event, file, stream, data product, direct integration, or hybrid implementation style"
          ],
          "steps": [
            {
              "text": "Use the Business Impact Canvas to identify availability, security, and data risks that influence architecture options.",
              "resourceId": "businessImpactCanvas",
              "resourceTitle": "Business Impact Canvas",
              "canvasId": "businessImpactCanvas"
            },
            {
              "text": "Use the Locations Canvas to capture geopolitical, regulatory, network, residency, and trust-boundary constraints.",
              "resourceId": "locationsCanvas",
              "resourceTitle": "Location Canvas",
              "canvasId": "locationsCanvas"
            },
            {
              "text": "Use the Capacity Canvas to capture current and future volumes, peaks, latency, caching, rate limiting, and scaling expectations.",
              "resourceId": "capacityCanvas",
              "resourceTitle": "Capacity Canvas",
              "canvasId": "capacityCanvas"
            },
            {
              "text": "Use metrics and analytics guidance to define how the chosen capability will be monitored and improved.",
              "resourceId": "api-metrics-and-analytics",
              "resourceTitle": "API Metrics And Analytics",
              "canvasId": null
            }
          ],
          "questions": [
            "Use the Business Impact Canvas to identify availability, security, and data risks that influence architecture options.",
            "Use the Locations Canvas to capture geopolitical, regulatory, network, residency, and trust-boundary constraints.",
            "Use the Capacity Canvas to capture current and future volumes, peaks, latency, caching, rate limiting, and scaling expectations.",
            "Use metrics and analytics guidance to define how the chosen capability will be monitored and improved.",
            "Compare viable architecture styles against the gathered requirements and document the selected pattern and rationale.",
            "Architecture choices should follow from evidence about business impact, locations, trust boundaries, capacity, latency, data ownership, consistency, operability, security, privacy, governance, and cost."
          ],
          "criteria": [
            "api-reusability",
            "hide-backend-discrepancies",
            "value-prop-validated",
            "consumer-segments-identified",
            "api-roadmap-defined"
          ],
          "criteriaDetails": [
            {
              "id": "api-reusability",
              "title": "The capability addresses a clear business need and is reusable by its intended consumers.",
              "description": "The API meets a clear business need and is reusable for multiple API consumers."
            },
            {
              "id": "hide-backend-discrepancies",
              "title": "The selected interface provides an appropriate abstraction for consumers.",
              "description": "The API is intended to shield consumers from backend complexity and inconsistencies."
            },
            {
              "id": "value-prop-validated",
              "title": "The capability value proposition has been validated with business and consumer stakeholders.",
              "description": "The API value proposition has been reviewed and validated with the relevant business and consumer stakeholders."
            },
            {
              "id": "consumer-segments-identified",
              "title": "Consumer segments are identified.",
              "description": "API consumer segments (internal and external) are identified."
            },
            {
              "id": "api-roadmap-defined",
              "title": "A high-level implementation roadmap is defined.",
              "description": "High-level roadmaps for API development are established."
            }
          ],
          "stakeholders": [
            {
              "id": "platform-architect",
              "sourceKey": "platform-architect",
              "sourceStakeholderId": "platform-architect",
              "title": "Platform Architect",
              "description": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
              "involvement": "lead",
              "responsibilities": [
                {
                  "resourceId": "locationsCanvas",
                  "resourceTitle": "Location Canvas",
                  "canvasId": "locationsCanvas",
                  "role": "suggested-answer-owner"
                }
              ]
            },
            {
              "id": "platform-owner",
              "sourceKey": "platform-owner",
              "sourceStakeholderId": "platform-owner",
              "title": "Platform Owner",
              "description": "Owns platform capabilities, roadmap, operational model, and service expectations.",
              "involvement": "lead",
              "responsibilities": []
            },
            {
              "id": "api-architect",
              "sourceKey": "api-architect",
              "sourceStakeholderId": "api-architect",
              "title": "API Architect",
              "description": "Owns API architecture, design principles, and interface contract quality.",
              "involvement": "core",
              "responsibilities": [
                {
                  "resourceId": "locationsCanvas",
                  "resourceTitle": "Location Canvas",
                  "canvasId": "locationsCanvas",
                  "role": "suggested-answer-owner"
                },
                {
                  "resourceId": "capacityCanvas",
                  "resourceTitle": "Capacity Canvas",
                  "canvasId": "capacityCanvas",
                  "role": "suggested-answer-owner"
                }
              ]
            },
            {
              "id": "api-product-owner",
              "sourceKey": "api-product-owner",
              "sourceStakeholderId": "api-product-owner",
              "title": "API Product Owner",
              "description": "Drives the API opportunity, prioritization, and product-level decisions across the lifecycle.",
              "involvement": "core",
              "responsibilities": [
                {
                  "resourceId": "businessImpactCanvas",
                  "resourceTitle": "Business Impact Canvas",
                  "canvasId": "businessImpactCanvas",
                  "role": "suggested-answer-owner"
                }
              ]
            },
            {
              "id": "automation-engineer",
              "sourceKey": "automation-engineer",
              "sourceStakeholderId": "automation-engineer",
              "title": "Automation Engineer",
              "description": "Implements, tests, integrates, and maintains automation solutions and supporting workflows.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "automation-owner",
              "sourceKey": "automation-owner",
              "sourceStakeholderId": "automation-owner",
              "title": "Automation Owner",
              "description": "Owns automation goals, business value, priorities, controls, and lifecycle outcomes.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "capability-owner",
              "sourceKey": "capability-owner",
              "sourceStakeholderId": "capability-owner",
              "title": "Capability Owner",
              "description": "Owns the capability vision, value, priorities, lifecycle, and reuse across consumers.",
              "involvement": "core",
              "responsibilities": [
                {
                  "resourceId": "businessImpactCanvas",
                  "resourceTitle": "Business Impact Canvas",
                  "canvasId": "businessImpactCanvas",
                  "role": "suggested-answer-owner"
                }
              ]
            },
            {
              "id": "compliance-specialist",
              "sourceKey": "compliance-specialist",
              "sourceStakeholderId": "compliance-specialist",
              "title": "Compliance and Legal Specialist",
              "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "domain-specialist",
              "sourceKey": "domain-specialist",
              "sourceStakeholderId": "domain-specialist",
              "title": "Domain Expert",
              "description": "Brings deep knowledge of the business domain, concepts, rules, and constraints the capability or interface must reflect.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "integration-architect",
              "sourceKey": "integration-architect",
              "sourceStakeholderId": "integration-architect",
              "title": "Integration Architect",
              "description": "Designs integration approaches and implementation styles that connect the capability or API with other systems.",
              "involvement": "core",
              "responsibilities": [
                {
                  "resourceId": "businessImpactCanvas",
                  "resourceTitle": "Business Impact Canvas",
                  "canvasId": "businessImpactCanvas",
                  "role": "suggested-answer-owner"
                }
              ]
            },
            {
              "id": "security-specialist",
              "sourceKey": "security-specialist",
              "sourceStakeholderId": "security-specialist",
              "title": "Security Specialist",
              "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "operations-specialist",
              "sourceKey": "operations-specialist",
              "sourceStakeholderId": "operations-specialist",
              "title": "Support and Operations Owner",
              "description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "api-consumer-specialist",
              "sourceKey": "api-consumer-specialist",
              "sourceStakeholderId": "api-consumer-specialist",
              "title": "API Consumer Representative",
              "description": "Represents the needs of developers, integrators, or other API consumers who use the API directly.",
              "involvement": "consulted",
              "responsibilities": []
            },
            {
              "id": "business-owner",
              "sourceKey": "business-owner",
              "sourceStakeholderId": "business-owner",
              "title": "Business Owner",
              "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
              "involvement": "consulted",
              "responsibilities": []
            },
            {
              "id": "api-engineer",
              "sourceKey": "api-engineer",
              "sourceStakeholderId": "api-engineer",
              "title": "Delivery Engineer",
              "description": "Owns implementation, automation, testing, and release flow concerns needed to deliver the capability, API, or automation reliably.",
              "involvement": "consulted",
              "responsibilities": []
            }
          ],
          "evidence": [
            "architecture-decision",
            "documentation",
            "platform-config",
            "metrics"
          ]
        },
        {
          "id": "business-goals",
          "slug": "method/business-goals",
          "icon": "business-center-outline",
          "title": "Business Goals - Align APIs with Business Objectives",
          "description": "Ensure APIs are aligned with business objectives and contribute to overall organizational goals.",
          "whyItMatters": "APIs should not be built in isolation; they must support and drive business objectives. This station helps teams align their APIs with strategic goals, ensuring they deliver real business value.",
          "applyInWork": "Provide business alignment frameworks, templates, and tools for defining API business value. Ensure teams regularly review and align APIs with changing business objectives.",
          "group": "Supporting Stations",
          "lifecycleStage": "supporting",
          "outcomes": [
            "APIs aligned with business objectives",
            "Clear business value defined for each API",
            "Stakeholder buy-in and support for API initiatives",
            "APIs contribute to organizational success"
          ],
          "steps": [
            {
              "text": "Define business objectives and how APIs can support them using **the Business Model Canvas**. If your business is to provide APIs, go through *the API Product Strategy station* and fill in **the API Business Model Canvas.**",
              "resourceId": "apiBusinessModelCanvas",
              "resourceTitle": "API Business Model Canvas",
              "canvasId": "apiBusinessModelCanvas"
            },
            {
              "text": "Identify key performance indicators (KPIs) to measure API success against business goals.",
              "resourceId": "api-metrics-and-analytics",
              "resourceTitle": "API Metrics And Analytics",
              "canvasId": null
            },
            {
              "text": "Engage stakeholders to ensure alignment and support for API initiatives.",
              "resourceId": "stakeholder-engagement-best-practices",
              "resourceTitle": "Stakeholder Engagement Best Practices",
              "canvasId": null
            }
          ],
          "questions": [
            "Define business objectives and how APIs can support them using **the Business Model Canvas**. If your business is to provide APIs, go through *the API Product Strategy station* and fill in **the API Business Model Canvas.**",
            "Identify key performance indicators (KPIs) to measure API success against business goals.",
            "Engage stakeholders to ensure alignment and support for API initiatives.",
            "Provide business alignment frameworks, templates, and tools for defining API business value. Ensure teams regularly review and align APIs with changing business objectives.",
            "APIs should not be built in isolation; they must support and drive business objectives. This station helps teams align their APIs with strategic goals, ensuring they deliver real business value."
          ],
          "criteria": [],
          "criteriaDetails": [],
          "stakeholders": [],
          "evidence": []
        },
        {
          "id": "api-design",
          "slug": "method/api-design",
          "icon": "api",
          "title": "Solution & Interface Design",
          "description": "Design the interface contract and interaction model after the architecture choice is justified.",
          "whyItMatters": "Once the architecture pattern is known, the design must turn capability requirements into clear interface contracts, interactions, schemas, data rules, lifecycle expectations, and consumer obligations.",
          "applyInWork": "Select the design resources that fit the chosen implementation style and document the interface contract before implementation.",
          "group": "Capability Lifecycle Core Stations",
          "lifecycleStage": "design",
          "outcomes": [
            "A validated interface contract for the selected implementation style",
            "Consistent interaction, data, event, file, workflow, or API contract decisions",
            "Design traceability back to capability and consumer requirements",
            "Designs aligned with domain models and interaction patterns"
          ],
          "steps": [
            {
              "text": "Reuse the Domain Canvas to confirm business objects, terms, rules, and ownership before contract design.",
              "resourceId": "domainCanvas",
              "resourceTitle": "Domain Canvas",
              "canvasId": "domainCanvas"
            },
            {
              "text": "Use the Interaction Canvas to describe how consumers, systems, or users interact with the capability.",
              "resourceId": "interactionCanvas",
              "resourceTitle": "Interaction Canvas",
              "canvasId": "interactionCanvas"
            },
            {
              "text": "Use REST design resources when the selected interface is a REST API.",
              "resourceId": "restCanvas",
              "resourceTitle": "REST Canvas",
              "canvasId": "restCanvas"
            },
            {
              "text": "Use Event Canvas resources when the selected interface is event-driven.",
              "resourceId": "eventCanvas",
              "resourceTitle": "Event Canvas",
              "canvasId": "eventCanvas"
            },
            {
              "text": "Use GraphQL design resources when the selected interface is GraphQL.",
              "resourceId": "graphqlCanvas",
              "resourceTitle": "GraphQL Canvas",
              "canvasId": "graphqlCanvas"
            },
            {
              "text": "Use the design principles and style guidance to align design decisions with shared rules and enable consistent audit validation.",
              "resourceId": "api-design-principles",
              "resourceTitle": "API Design Principles",
              "canvasId": null
            },
            {
              "text": "Apply contract-first or design-first approaches to capture and validate the interface contract before implementation.",
              "resourceId": "contract-first-design",
              "resourceTitle": "Contract First Design",
              "canvasId": null
            },
            {
              "text": "Use the audit checklist to ensure the design meets functional and non-functional requirements, including security, performance, and compliance.",
              "resourceId": "api-audit-checklist",
              "resourceTitle": "API Audit Checklist",
              "canvasId": null
            }
          ],
          "questions": [
            "Reuse the Domain Canvas to confirm business objects, terms, rules, and ownership before contract design.",
            "Use the Interaction Canvas to describe how consumers, systems, or users interact with the capability.",
            "Use REST design resources when the selected interface is a REST API.",
            "Use Event Canvas resources when the selected interface is event-driven.",
            "Use GraphQL design resources when the selected interface is GraphQL.",
            "Use the design principles and style guidance to align design decisions with shared rules and enable consistent audit validation.",
            "Apply contract-first or design-first approaches to capture and validate the interface contract before implementation.",
            "Use the audit checklist to ensure the design meets functional and non-functional requirements, including security, performance, and compliance.",
            "Select the design resources that fit the chosen implementation style and document the interface contract before implementation.",
            "Once the architecture pattern is known, the design must turn capability requirements into clear interface contracts, interactions, schemas, data rules, lifecycle expectations, and consumer obligations."
          ],
          "criteria": [
            "architecture-patterns-validated",
            "hide-backend-discrepancies",
            "design-reflects-business-value",
            "api-consistency"
          ],
          "criteriaDetails": [
            {
              "id": "architecture-patterns-validated",
              "title": "The chosen architecture, platform, and implementation style have been validated with the relevant architecture, security, and platform stakeholders.",
              "description": "The chosen API architecture and platform patterns have been validated with the relevant architecture, security, and platform stakeholders."
            },
            {
              "id": "hide-backend-discrepancies",
              "title": "The selected interface provides an appropriate abstraction for consumers.",
              "description": "The API is intended to shield consumers from backend complexity and inconsistencies."
            },
            {
              "id": "design-reflects-business-value",
              "title": "The interface design and exposed capabilities trace back to business value and consumer needs.",
              "description": "The API design and exposed capabilities clearly trace back to business value and user needs."
            },
            {
              "id": "api-consistency",
              "title": "The interface design follows agreed design standards and conventions.",
              "description": "The API design follows our shared API product and design conventions."
            }
          ],
          "stakeholders": [
            {
              "id": "api-designer",
              "sourceKey": "api-designer",
              "sourceStakeholderId": "api-designer",
              "title": "API Designer",
              "description": "Shapes the interface contract, interaction model, consistency, and usability of the exposed capabilities.",
              "involvement": "lead",
              "responsibilities": []
            },
            {
              "id": "automation-engineer",
              "sourceKey": "automation-engineer",
              "sourceStakeholderId": "automation-engineer",
              "title": "Automation Engineer",
              "description": "Implements, tests, integrates, and maintains automation solutions and supporting workflows.",
              "involvement": "lead",
              "responsibilities": []
            },
            {
              "id": "integration-architect",
              "sourceKey": "integration-architect",
              "sourceStakeholderId": "integration-architect",
              "title": "Integration Architect",
              "description": "Designs integration approaches and implementation styles that connect the capability or API with other systems.",
              "involvement": "lead",
              "responsibilities": []
            },
            {
              "id": "api-consumer-specialist",
              "sourceKey": "api-consumer-specialist",
              "sourceStakeholderId": "api-consumer-specialist",
              "title": "API Consumer Representative",
              "description": "Represents the needs of developers, integrators, or other API consumers who use the API directly.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "api-product-owner",
              "sourceKey": "api-product-owner",
              "sourceStakeholderId": "api-product-owner",
              "title": "API Product Owner",
              "description": "Drives the API opportunity, prioritization, and product-level decisions across the lifecycle.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "automation-owner",
              "sourceKey": "automation-owner",
              "sourceStakeholderId": "automation-owner",
              "title": "Automation Owner",
              "description": "Owns automation goals, business value, priorities, controls, and lifecycle outcomes.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "capability-owner",
              "sourceKey": "capability-owner",
              "sourceStakeholderId": "capability-owner",
              "title": "Capability Owner",
              "description": "Owns the capability vision, value, priorities, lifecycle, and reuse across consumers.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "compliance-specialist",
              "sourceKey": "compliance-specialist",
              "sourceStakeholderId": "compliance-specialist",
              "title": "Compliance and Legal Specialist",
              "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "domain-specialist",
              "sourceKey": "domain-specialist",
              "sourceStakeholderId": "domain-specialist",
              "title": "Domain Expert",
              "description": "Brings deep knowledge of the business domain, concepts, rules, and constraints the capability or interface must reflect.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "platform-architect",
              "sourceKey": "platform-architect",
              "sourceStakeholderId": "platform-architect",
              "title": "Platform Architect",
              "description": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "process-owner",
              "sourceKey": "process-owner",
              "sourceStakeholderId": "process-owner",
              "title": "Process Owner",
              "description": "Owns the business process being automated, including objectives, rules, outcomes, and improvement priorities.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "security-specialist",
              "sourceKey": "security-specialist",
              "sourceStakeholderId": "security-specialist",
              "title": "Security Specialist",
              "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "business-owner",
              "sourceKey": "business-owner",
              "sourceStakeholderId": "business-owner",
              "title": "Business Owner",
              "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
              "involvement": "consulted",
              "responsibilities": []
            },
            {
              "id": "api-engineer",
              "sourceKey": "api-engineer",
              "sourceStakeholderId": "api-engineer",
              "title": "Delivery Engineer",
              "description": "Owns implementation, automation, testing, and release flow concerns needed to deliver the capability, API, or automation reliably.",
              "involvement": "consulted",
              "responsibilities": []
            },
            {
              "id": "api-devrel-specialist",
              "sourceKey": "api-devrel-specialist",
              "sourceStakeholderId": "api-devrel-specialist",
              "title": "Documentation and DevRel Owner",
              "description": "Owns onboarding content, developer communication, and documentation quality for API consumers.",
              "involvement": "consulted",
              "responsibilities": []
            }
          ],
          "evidence": [
            "spec",
            "contract",
            "design-artifact",
            "documentation"
          ]
        },
        {
          "id": "competitive-analysis",
          "slug": "method/competitive-analysis",
          "icon": "trophy-outline",
          "title": "Competitive Analysis - Stay Ahead in the API Market",
          "description": "Analyze competitors' APIs to identify strengths, weaknesses, and opportunities for differentiation.",
          "whyItMatters": "Understanding the competitive landscape helps teams identify gaps, opportunities, and areas for improvement in their APIs. This station provides tools to analyze competitors and inform API strategy.",
          "applyInWork": "Provide competitive analysis tools, templates, and resources. Ensure teams regularly analyze competitors and incorporate insights into API strategy and design.",
          "group": "Supporting Stations",
          "lifecycleStage": "supporting",
          "outcomes": [
            "Competitor APIs analyzed for strengths and weaknesses",
            "Opportunities for differentiation identified",
            "API strategy informed by competitive insights",
            "Increased competitiveness in the API market"
          ],
          "steps": [
            {
              "text": "Conduct a competitive analysis to identify key competitors, their API offerings, and their strengths and weaknesses.",
              "resourceId": "competitor-analysis-template",
              "resourceTitle": "Competitor Analysis Template",
              "canvasId": null
            },
            {
              "text": "Identify gaps in the market that your APIs can fill, based on competitor offerings.",
              "resourceId": "ecosystem-vision-template",
              "resourceTitle": "Ecosystem Vision Template",
              "canvasId": null
            },
            {
              "text": "Develop a differentiation strategy that highlights unique features and benefits of your APIs.",
              "resourceId": "ecosystem-vision-template",
              "resourceTitle": "Ecosystem Vision Template",
              "canvasId": null
            }
          ],
          "questions": [
            "Conduct a competitive analysis to identify key competitors, their API offerings, and their strengths and weaknesses.",
            "Identify gaps in the market that your APIs can fill, based on competitor offerings.",
            "Develop a differentiation strategy that highlights unique features and benefits of your APIs.",
            "Provide competitive analysis tools, templates, and resources. Ensure teams regularly analyze competitors and incorporate insights into API strategy and design.",
            "Understanding the competitive landscape helps teams identify gaps, opportunities, and areas for improvement in their APIs. This station provides tools to analyze competitors and inform API strategy."
          ],
          "criteria": [],
          "criteriaDetails": [],
          "stakeholders": [],
          "evidence": []
        },
        {
          "id": "api-delivery",
          "slug": "method/api-delivery",
          "icon": "code",
          "title": "Delivery & Operations",
          "description": "Deliver the selected implementation style with appropriate engineering, testing, security, automation, and operational practices.",
          "whyItMatters": "A reusable capability needs reliable delivery and operations regardless of whether it becomes an API, event stream, file exchange, data product, or direct integration.",
          "applyInWork": "Apply delivery, testing, CI/CD, operations, and security guidance to the chosen implementation style.",
          "group": "Capability Lifecycle Core Stations",
          "lifecycleStage": "delivery",
          "outcomes": [
            "A delivered capability aligned with the validated interface contract",
            "Automated testing, deployment, and environment controls",
            "Security, operations, and quality practices appropriate to the chosen pattern",
            "Traceable delivery and release controls"
          ],
          "steps": [
            {
              "text": "Use development best practices to implement the validated interface contract with established frameworks, libraries, and team standards.",
              "resourceId": "api-development-best-practices",
              "resourceTitle": "API Development Best Practices",
              "canvasId": null
            },
            {
              "text": "Build the implementation from the validated interface contract using established frameworks, libraries, and team standards.",
              "resourceId": "api-development-best-practices",
              "resourceTitle": "API Development Best Practices",
              "canvasId": null
            },
            {
              "text": "Use testing guidance to verify functionality, data quality, compatibility, security, performance, resilience, and recovery expectations.",
              "resourceId": "api-testing-best-practices",
              "resourceTitle": "API Testing Best Practices",
              "canvasId": null
            },
            {
              "text": "Use CI/CD guidance to automate build, test, deployment, configuration, and traceability.",
              "resourceId": "apiops-CI-CD-for-apis",
              "resourceTitle": "APIOps CI/CD For APIs",
              "canvasId": null
            },
            {
              "text": "Use security guidance to protect data, access, credentials, and platform boundaries.",
              "resourceId": "api-security-best-practices",
              "resourceTitle": "API Security Best Practices",
              "canvasId": null
            },
            {
              "text": "Use the audit checklist to ensure the solution meets functional and non-functional requirements, including security, performance, and compliance.",
              "resourceId": "api-audit-checklist",
              "resourceTitle": "API Audit Checklist",
              "canvasId": null
            }
          ],
          "questions": [
            "Use development best practices to implement the validated interface contract with established frameworks, libraries, and team standards.",
            "Build the implementation from the validated interface contract using established frameworks, libraries, and team standards.",
            "Use testing guidance to verify functionality, data quality, compatibility, security, performance, resilience, and recovery expectations.",
            "Use CI/CD guidance to automate build, test, deployment, configuration, and traceability.",
            "Use security guidance to protect data, access, credentials, and platform boundaries.",
            "Use the audit checklist to ensure the solution meets functional and non-functional requirements, including security, performance, and compliance.",
            "Apply delivery, testing, CI/CD, operations, and security guidance to the chosen implementation style.",
            "A reusable capability needs reliable delivery and operations regardless of whether it becomes an API, event stream, file exchange, data product, or direct integration."
          ],
          "criteria": [
            "architecture-patterns-validated",
            "hide-backend-discrepancies",
            "design-reflects-business-value",
            "api-consistency"
          ],
          "criteriaDetails": [
            {
              "id": "architecture-patterns-validated",
              "title": "The chosen architecture, platform, and implementation style have been validated with the relevant architecture, security, and platform stakeholders.",
              "description": "The chosen API architecture and platform patterns have been validated with the relevant architecture, security, and platform stakeholders."
            },
            {
              "id": "hide-backend-discrepancies",
              "title": "The selected interface provides an appropriate abstraction for consumers.",
              "description": "The API is intended to shield consumers from backend complexity and inconsistencies."
            },
            {
              "id": "design-reflects-business-value",
              "title": "The interface design and exposed capabilities trace back to business value and consumer needs.",
              "description": "The API design and exposed capabilities clearly trace back to business value and user needs."
            },
            {
              "id": "api-consistency",
              "title": "The interface design follows agreed design standards and conventions.",
              "description": "The API design follows our shared API product and design conventions."
            }
          ],
          "stakeholders": [
            {
              "id": "automation-engineer",
              "sourceKey": "automation-engineer",
              "sourceStakeholderId": "automation-engineer",
              "title": "Automation Engineer",
              "description": "Implements, tests, integrates, and maintains automation solutions and supporting workflows.",
              "involvement": "lead",
              "responsibilities": []
            },
            {
              "id": "api-engineer",
              "sourceKey": "api-engineer",
              "sourceStakeholderId": "api-engineer",
              "title": "Delivery Engineer",
              "description": "Owns implementation, automation, testing, and release flow concerns needed to deliver the capability, API, or automation reliably.",
              "involvement": "lead",
              "responsibilities": []
            },
            {
              "id": "api-designer",
              "sourceKey": "api-designer",
              "sourceStakeholderId": "api-designer",
              "title": "API Designer",
              "description": "Shapes the interface contract, interaction model, consistency, and usability of the exposed capabilities.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "automation-owner",
              "sourceKey": "automation-owner",
              "sourceStakeholderId": "automation-owner",
              "title": "Automation Owner",
              "description": "Owns automation goals, business value, priorities, controls, and lifecycle outcomes.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "integration-architect",
              "sourceKey": "integration-architect",
              "sourceStakeholderId": "integration-architect",
              "title": "Integration Architect",
              "description": "Designs integration approaches and implementation styles that connect the capability or API with other systems.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "platform-architect",
              "sourceKey": "platform-architect",
              "sourceStakeholderId": "platform-architect",
              "title": "Platform Architect",
              "description": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "security-specialist",
              "sourceKey": "security-specialist",
              "sourceStakeholderId": "security-specialist",
              "title": "Security Specialist",
              "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "operations-specialist",
              "sourceKey": "operations-specialist",
              "sourceStakeholderId": "operations-specialist",
              "title": "Support and Operations Owner",
              "description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "api-product-owner",
              "sourceKey": "api-product-owner",
              "sourceStakeholderId": "api-product-owner",
              "title": "API Product Owner",
              "description": "Drives the API opportunity, prioritization, and product-level decisions across the lifecycle.",
              "involvement": "consulted",
              "responsibilities": []
            },
            {
              "id": "business-owner",
              "sourceKey": "business-owner",
              "sourceStakeholderId": "business-owner",
              "title": "Business Owner",
              "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
              "involvement": "consulted",
              "responsibilities": []
            },
            {
              "id": "capability-owner",
              "sourceKey": "capability-owner",
              "sourceStakeholderId": "capability-owner",
              "title": "Capability Owner",
              "description": "Owns the capability vision, value, priorities, lifecycle, and reuse across consumers.",
              "involvement": "consulted",
              "responsibilities": []
            },
            {
              "id": "compliance-specialist",
              "sourceKey": "compliance-specialist",
              "sourceStakeholderId": "compliance-specialist",
              "title": "Compliance and Legal Specialist",
              "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
              "involvement": "consulted",
              "responsibilities": []
            },
            {
              "id": "partner-specialist",
              "sourceKey": "partner-specialist",
              "sourceStakeholderId": "partner-specialist",
              "title": "Partner or Vendor Manager",
              "description": "Coordinates external partner, supplier, or vendor relationships that influence capability or API strategy and delivery.",
              "involvement": "consulted",
              "responsibilities": []
            },
            {
              "id": "process-owner",
              "sourceKey": "process-owner",
              "sourceStakeholderId": "process-owner",
              "title": "Process Owner",
              "description": "Owns the business process being automated, including objectives, rules, outcomes, and improvement priorities.",
              "involvement": "consulted",
              "responsibilities": []
            }
          ],
          "evidence": [
            "implementation",
            "pipeline-config",
            "test-report",
            "security-report"
          ]
        },
        {
          "id": "ecosystem-vision",
          "slug": "method/ecosystem-vision",
          "icon": "globe-book-rounded",
          "title": "Ecosystem Vision - Build APIs for a Thriving Ecosystem",
          "description": "Create a vision for how your APIs fit into a larger ecosystem, enabling collaboration and innovation.",
          "whyItMatters": "APIs are not standalone products; they are part of a larger ecosystem. This station helps teams define how their APIs interact with other systems, platforms, and services to create a thriving ecosystem that fosters collaboration and innovation.",
          "applyInWork": "Provide ecosystem vision frameworks, partner engagement strategies, and integration guidelines. Ensure teams design APIs with the ecosystem in mind and foster collaboration among partners.",
          "group": "Supporting Stations",
          "lifecycleStage": "supporting",
          "outcomes": [
            "Clear ecosystem vision defined for APIs",
            "APIs designed to enable collaboration and integration",
            "Ecosystem partners identified and engaged",
            "APIs contribute to a vibrant ecosystem"
          ],
          "steps": [
            {
              "text": "Define the ecosystem vision for your APIs, including how they will interact with other systems and platforms.",
              "resourceId": "ecosystem-vision-template",
              "resourceTitle": "Ecosystem Vision Template",
              "canvasId": null
            },
            {
              "text": "Identify key ecosystem partners and stakeholders who will benefit from or contribute to the ecosystem.",
              "resourceId": "ecosystem-vision-template",
              "resourceTitle": "Ecosystem Vision Template",
              "canvasId": null
            },
            {
              "text": "Design APIs to enable seamless integration and collaboration within the ecosystem.",
              "resourceId": "ecosystem-vision-template",
              "resourceTitle": "Ecosystem Vision Template",
              "canvasId": null
            }
          ],
          "questions": [
            "Define the ecosystem vision for your APIs, including how they will interact with other systems and platforms.",
            "Identify key ecosystem partners and stakeholders who will benefit from or contribute to the ecosystem.",
            "Design APIs to enable seamless integration and collaboration within the ecosystem.",
            "Provide ecosystem vision frameworks, partner engagement strategies, and integration guidelines. Ensure teams design APIs with the ecosystem in mind and foster collaboration among partners.",
            "APIs are not standalone products; they are part of a larger ecosystem. This station helps teams define how their APIs interact with other systems, platforms, and services to create a thriving ecosystem that fosters collaboration and innovation."
          ],
          "criteria": [],
          "criteriaDetails": [],
          "stakeholders": [],
          "evidence": []
        },
        {
          "id": "api-audit",
          "slug": "method/api-audit",
          "icon": "check-box-outline",
          "title": "Quality & Readiness Assurance",
          "description": "Audit the capability interface contract, controls, support model, observability, documentation, and lifecycle readiness before release.",
          "whyItMatters": "Reusable capabilities create operational, data, security, privacy, compliance, and consumer-impact risks. Readiness checks reduce surprises before release or production use.",
          "applyInWork": "Use audit and compliance resources to verify that the capability is ready for controlled release and reuse.",
          "group": "Capability Lifecycle Core Stations",
          "lifecycleStage": "publishing",
          "outcomes": [
            "Documented readiness for release and reuse",
            "Known gaps and mitigations before release",
            "Evidence for governance, compliance, support, and operational approval",
            "Reduced risk of issues in production"
          ],
          "steps": [
            {
              "text": "Use the audit checklist as a reusable quality checklist for interface contract, documentation, security, performance, and compliance readiness.",
              "resourceId": "api-audit-checklist",
              "resourceTitle": "API Audit Checklist",
              "canvasId": null
            },
            {
              "text": "Use checklists, linters, and testing tools to verify consistency and conformance with standards.",
              "resourceId": "api-compliance-best-practices",
              "resourceTitle": "API Compliance Best Practices",
              "canvasId": null
            },
            {
              "text": "Collaborate with governance teams and domain experts to ensure the capability is ready for production.",
              "resourceTitle": "",
              "canvasId": null
            }
          ],
          "questions": [
            "Use the audit checklist as a reusable quality checklist for interface contract, documentation, security, performance, and compliance readiness.",
            "Use checklists, linters, and testing tools to verify consistency and conformance with standards.",
            "Collaborate with governance teams and domain experts to ensure the capability is ready for production.",
            "Use audit and compliance resources to verify that the capability is ready for controlled release and reuse.",
            "Reusable capabilities create operational, data, security, privacy, compliance, and consumer-impact risks. Readiness checks reduce surprises before release or production use."
          ],
          "criteria": [
            "architecture-patterns-validated",
            "design-reflects-business-value",
            "api-description-available",
            "api-consistency",
            "api-contract-tested"
          ],
          "criteriaDetails": [
            {
              "id": "architecture-patterns-validated",
              "title": "The chosen architecture, platform, and implementation style have been validated with the relevant architecture, security, and platform stakeholders.",
              "description": "The chosen API architecture and platform patterns have been validated with the relevant architecture, security, and platform stakeholders."
            },
            {
              "id": "design-reflects-business-value",
              "title": "The interface design and exposed capabilities trace back to business value and consumer needs.",
              "description": "The API design and exposed capabilities clearly trace back to business value and user needs."
            },
            {
              "id": "api-description-available",
              "title": "The interface and its capabilities are documented clearly enough for review, audit, and onboarding.",
              "description": "The API and its exposed capabilities are described clearly enough for review, audit, and onboarding."
            },
            {
              "id": "api-consistency",
              "title": "The interface design follows agreed design standards and conventions.",
              "description": "The API design follows our shared API product and design conventions."
            },
            {
              "id": "api-contract-tested",
              "title": "The interface contract has been validated and tested against functional and non-functional requirements.",
              "description": "The API contract is tested and meets functional and non-functional requirements."
            }
          ],
          "stakeholders": [
            {
              "id": "governance-specialist",
              "sourceKey": "governance-specialist",
              "sourceStakeholderId": "governance-specialist",
              "title": "API Governance Owner",
              "description": "Represents review, audit, and organization-wide governance practices for API quality and conformity.",
              "involvement": "lead",
              "responsibilities": []
            },
            {
              "id": "api-designer",
              "sourceKey": "api-designer",
              "sourceStakeholderId": "api-designer",
              "title": "API Designer",
              "description": "Shapes the interface contract, interaction model, consistency, and usability of the exposed capabilities.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "automation-owner",
              "sourceKey": "automation-owner",
              "sourceStakeholderId": "automation-owner",
              "title": "Automation Owner",
              "description": "Owns automation goals, business value, priorities, controls, and lifecycle outcomes.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "capability-owner",
              "sourceKey": "capability-owner",
              "sourceStakeholderId": "capability-owner",
              "title": "Capability Owner",
              "description": "Owns the capability vision, value, priorities, lifecycle, and reuse across consumers.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "compliance-specialist",
              "sourceKey": "compliance-specialist",
              "sourceStakeholderId": "compliance-specialist",
              "title": "Compliance and Legal Specialist",
              "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "api-engineer",
              "sourceKey": "api-engineer",
              "sourceStakeholderId": "api-engineer",
              "title": "Delivery Engineer",
              "description": "Owns implementation, automation, testing, and release flow concerns needed to deliver the capability, API, or automation reliably.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "integration-architect",
              "sourceKey": "integration-architect",
              "sourceStakeholderId": "integration-architect",
              "title": "Integration Architect",
              "description": "Designs integration approaches and implementation styles that connect the capability or API with other systems.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "process-owner",
              "sourceKey": "process-owner",
              "sourceStakeholderId": "process-owner",
              "title": "Process Owner",
              "description": "Owns the business process being automated, including objectives, rules, outcomes, and improvement priorities.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "security-specialist",
              "sourceKey": "security-specialist",
              "sourceStakeholderId": "security-specialist",
              "title": "Security Specialist",
              "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "operations-specialist",
              "sourceKey": "operations-specialist",
              "sourceStakeholderId": "operations-specialist",
              "title": "Support and Operations Owner",
              "description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "api-product-owner",
              "sourceKey": "api-product-owner",
              "sourceStakeholderId": "api-product-owner",
              "title": "API Product Owner",
              "description": "Drives the API opportunity, prioritization, and product-level decisions across the lifecycle.",
              "involvement": "consulted",
              "responsibilities": []
            },
            {
              "id": "automation-engineer",
              "sourceKey": "automation-engineer",
              "sourceStakeholderId": "automation-engineer",
              "title": "Automation Engineer",
              "description": "Implements, tests, integrates, and maintains automation solutions and supporting workflows.",
              "involvement": "consulted",
              "responsibilities": []
            },
            {
              "id": "business-owner",
              "sourceKey": "business-owner",
              "sourceStakeholderId": "business-owner",
              "title": "Business Owner",
              "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
              "involvement": "consulted",
              "responsibilities": []
            },
            {
              "id": "platform-architect",
              "sourceKey": "platform-architect",
              "sourceStakeholderId": "platform-architect",
              "title": "Platform Architect",
              "description": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
              "involvement": "consulted",
              "responsibilities": []
            }
          ],
          "evidence": [
            "audit-report",
            "compliance-report",
            "security-report",
            "test-report"
          ]
        },
        {
          "id": "scalable-infrastructure",
          "slug": "method/scalable-infrastructure",
          "icon": "cloud-done-outline",
          "title": "Scalable Infrastructure - Build APIs on a Solid Foundation",
          "description": "Ensure your API infrastructure can scale to meet growing demand and support high availability.",
          "whyItMatters": "APIs must be built on a robust infrastructure that can handle increasing traffic and ensure high availability. This station provides guidelines for designing and implementing scalable infrastructure that supports API growth and performance.",
          "applyInWork": "Provide infrastructure design guidelines, cloud-native patterns, and monitoring tools. Ensure teams implement scalable infrastructure that can adapt to changing demands and support API performance.",
          "group": "Supporting Stations",
          "lifecycleStage": "supporting",
          "outcomes": [
            "Scalable and resilient API infrastructure",
            "High availability and performance under load",
            "Infrastructure designed for future growth",
            "Reduced downtime and improved user experience"
          ],
          "steps": [
            {
              "text": "Design API infrastructure to be scalable and resilient, using cloud-native patterns and technologies.",
              "resourceId": "scalable-infrastructure-best-practices",
              "resourceTitle": "Scalable Infrastructure Best Practices",
              "canvasId": null
            },
            {
              "text": "Implement load balancing, caching, and other techniques to ensure high availability and performance. Collect infrastructure requirements from API teams using Capacity Canvas",
              "resourceId": "capacityCanvas",
              "resourceTitle": "Capacity Canvas",
              "canvasId": "capacityCanvas"
            },
            {
              "text": "Monitor infrastructure performance and capacity to ensure it can handle growing demand.",
              "resourceId": "scalable-infrastructure-best-practices",
              "resourceTitle": "Scalable Infrastructure Best Practices",
              "canvasId": null
            }
          ],
          "questions": [
            "Design API infrastructure to be scalable and resilient, using cloud-native patterns and technologies.",
            "Implement load balancing, caching, and other techniques to ensure high availability and performance. Collect infrastructure requirements from API teams using Capacity Canvas",
            "Monitor infrastructure performance and capacity to ensure it can handle growing demand.",
            "Provide infrastructure design guidelines, cloud-native patterns, and monitoring tools. Ensure teams implement scalable infrastructure that can adapt to changing demands and support API performance.",
            "APIs must be built on a robust infrastructure that can handle increasing traffic and ensure high availability. This station provides guidelines for designing and implementing scalable infrastructure that supports API growth and performance."
          ],
          "criteria": [],
          "criteriaDetails": [],
          "stakeholders": [],
          "evidence": []
        },
        {
          "id": "api-publishing",
          "slug": "method/api-publishing",
          "icon": "deployed-code-outline",
          "title": "Publishing & Enablement",
          "description": "Publish reusable capability information so consumers can discover, request, onboard, use, and get support.",
          "whyItMatters": "Reusable capabilities only create value when consumers can find them, understand their interface contract and service expectations, request access, and know who owns support and lifecycle decisions.",
          "applyInWork": "Publish ownership, documentation, onboarding, support contacts, service expectations, lifecycle status, and access request paths.",
          "group": "Capability Lifecycle Core Stations",
          "lifecycleStage": "publishing",
          "outcomes": [
            "A discoverable reusable capability",
            "Clear onboarding, access, support, and service expectations",
            "Lifecycle and ownership information available to consumers and governance teams",
            "Consumers enabled to use and reuse the capability"
          ],
          "steps": [
            {
              "text": "Publish capability information to the appropriate catalogs, portals, gateways, or environments to support reuse by multiple consumers.",
              "resourceId": "apiops-CI-CD-for-apis",
              "resourceTitle": "APIOps CI/CD For APIs",
              "canvasId": null
            },
            {
              "text": "Document how consumers find and use the capability, including onboarding processes and registration.",
              "resourceId": "api-onboarding-best-practices",
              "resourceTitle": "API Onboarding Best Practices",
              "canvasId": null
            },
            {
              "text": "Ensure security models, access configuration, and legal terms are clear and accessible to consumers.",
              "resourceId": "api-audit-checklist",
              "resourceTitle": "API Audit Checklist",
              "canvasId": null
            }
          ],
          "questions": [
            "Publish capability information to the appropriate catalogs, portals, gateways, or environments to support reuse by multiple consumers.",
            "Document how consumers find and use the capability, including onboarding processes and registration.",
            "Ensure security models, access configuration, and legal terms are clear and accessible to consumers.",
            "Publish ownership, documentation, onboarding, support contacts, service expectations, lifecycle status, and access request paths.",
            "Reusable capabilities only create value when consumers can find them, understand their interface contract and service expectations, request access, and know who owns support and lifecycle decisions."
          ],
          "criteria": [
            "audit-passed",
            "audit-reports-shared",
            "api-ready-for-publishing",
            "api-documentation-ready"
          ],
          "criteriaDetails": [
            {
              "id": "audit-passed",
              "title": "The solution passes quality, security, compliance, and readiness checks.",
              "description": "The API passes compliance, security, and audit checks."
            },
            {
              "id": "audit-reports-shared",
              "title": "Audit findings and remediation decisions are shared with the relevant stakeholders.",
              "description": "Audit findings and remediation decisions are shared with the relevant stakeholders."
            },
            {
              "id": "api-ready-for-publishing",
              "title": "The capability is ready to be published or released through the selected delivery mechanism.",
              "description": "The API is ready to be deployed and exposed through the intended gateways and environments."
            },
            {
              "id": "api-documentation-ready",
              "title": "Consumer-facing documentation and onboarding materials are ready.",
              "description": "Consumer-facing API documentation is complete enough for publishing and onboarding."
            }
          ],
          "stakeholders": [
            {
              "id": "api-product-owner",
              "sourceKey": "api-product-owner",
              "sourceStakeholderId": "api-product-owner",
              "title": "API Product Owner",
              "description": "Drives the API opportunity, prioritization, and product-level decisions across the lifecycle.",
              "involvement": "lead",
              "responsibilities": []
            },
            {
              "id": "automation-owner",
              "sourceKey": "automation-owner",
              "sourceStakeholderId": "automation-owner",
              "title": "Automation Owner",
              "description": "Owns automation goals, business value, priorities, controls, and lifecycle outcomes.",
              "involvement": "lead",
              "responsibilities": []
            },
            {
              "id": "capability-owner",
              "sourceKey": "capability-owner",
              "sourceStakeholderId": "capability-owner",
              "title": "Capability Owner",
              "description": "Owns the capability vision, value, priorities, lifecycle, and reuse across consumers.",
              "involvement": "lead",
              "responsibilities": []
            },
            {
              "id": "integration-architect",
              "sourceKey": "integration-architect",
              "sourceStakeholderId": "integration-architect",
              "title": "Integration Architect",
              "description": "Designs integration approaches and implementation styles that connect the capability or API with other systems.",
              "involvement": "lead",
              "responsibilities": []
            },
            {
              "id": "api-consumer-specialist",
              "sourceKey": "api-consumer-specialist",
              "sourceStakeholderId": "api-consumer-specialist",
              "title": "API Consumer Representative",
              "description": "Represents the needs of developers, integrators, or other API consumers who use the API directly.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "compliance-specialist",
              "sourceKey": "compliance-specialist",
              "sourceStakeholderId": "compliance-specialist",
              "title": "Compliance and Legal Specialist",
              "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "api-devrel-specialist",
              "sourceKey": "api-devrel-specialist",
              "sourceStakeholderId": "api-devrel-specialist",
              "title": "Documentation and DevRel Owner",
              "description": "Owns onboarding content, developer communication, and documentation quality for API consumers.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "partner-specialist",
              "sourceKey": "partner-specialist",
              "sourceStakeholderId": "partner-specialist",
              "title": "Partner or Vendor Manager",
              "description": "Coordinates external partner, supplier, or vendor relationships that influence capability or API strategy and delivery.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "process-owner",
              "sourceKey": "process-owner",
              "sourceStakeholderId": "process-owner",
              "title": "Process Owner",
              "description": "Owns the business process being automated, including objectives, rules, outcomes, and improvement priorities.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "security-specialist",
              "sourceKey": "security-specialist",
              "sourceStakeholderId": "security-specialist",
              "title": "Security Specialist",
              "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "operations-specialist",
              "sourceKey": "operations-specialist",
              "sourceStakeholderId": "operations-specialist",
              "title": "Support and Operations Owner",
              "description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "automation-engineer",
              "sourceKey": "automation-engineer",
              "sourceStakeholderId": "automation-engineer",
              "title": "Automation Engineer",
              "description": "Implements, tests, integrates, and maintains automation solutions and supporting workflows.",
              "involvement": "consulted",
              "responsibilities": []
            },
            {
              "id": "business-owner",
              "sourceKey": "business-owner",
              "sourceStakeholderId": "business-owner",
              "title": "Business Owner",
              "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
              "involvement": "consulted",
              "responsibilities": []
            },
            {
              "id": "api-engineer",
              "sourceKey": "api-engineer",
              "sourceStakeholderId": "api-engineer",
              "title": "Delivery Engineer",
              "description": "Owns implementation, automation, testing, and release flow concerns needed to deliver the capability, API, or automation reliably.",
              "involvement": "consulted",
              "responsibilities": []
            }
          ],
          "evidence": [
            "gateway-config",
            "developer-portal",
            "documentation",
            "release-record"
          ]
        },
        {
          "id": "legal-and-compliance",
          "slug": "method/legal-and-compliance",
          "icon": "gavel-rounded",
          "title": "Legal and Compliance - Ensure APIs Meet Regulatory Standards",
          "description": "Ensure APIs comply with legal and regulatory requirements, protecting your organization and users.",
          "whyItMatters": "APIs must adhere to legal and regulatory standards to protect your organization and users. This station provides tools and guidelines for ensuring APIs meet compliance requirements, reducing legal risks and ensuring data protection.",
          "applyInWork": "Provide legal and compliance frameworks, checklists, and tools for ensuring API compliance. Ensure teams understand and implement legal requirements in API design, development, and publishing.",
          "group": "Supporting Stations",
          "lifecycleStage": "supporting",
          "outcomes": [
            "APIs compliant with legal and regulatory standards",
            "Data protection and privacy requirements met",
            "Legal risks identified and mitigated",
            "Clear documentation of compliance measures"
          ],
          "steps": [
            {
              "text": "Identify legal and regulatory requirements that apply to your APIs, such as data protection, privacy, and security standards.",
              "resourceId": "api-compliance-best-practices",
              "resourceTitle": "API Compliance Best Practices",
              "canvasId": null
            },
            {
              "text": "Implement measures to ensure APIs comply with these requirements, including data encryption, access controls, and audit trails.",
              "resourceId": "api-compliance-best-practices",
              "resourceTitle": "API Compliance Best Practices",
              "canvasId": null
            },
            {
              "text": "Document compliance measures and ensure they are communicated to stakeholders and consumers.",
              "resourceId": "api-compliance-best-practices",
              "resourceTitle": "API Compliance Best Practices",
              "canvasId": null
            }
          ],
          "questions": [
            "Identify legal and regulatory requirements that apply to your APIs, such as data protection, privacy, and security standards.",
            "Implement measures to ensure APIs comply with these requirements, including data encryption, access controls, and audit trails.",
            "Document compliance measures and ensure they are communicated to stakeholders and consumers.",
            "Provide legal and compliance frameworks, checklists, and tools for ensuring API compliance. Ensure teams understand and implement legal requirements in API design, development, and publishing.",
            "APIs must adhere to legal and regulatory standards to protect your organization and users. This station provides tools and guidelines for ensuring APIs meet compliance requirements, reducing legal risks and ensuring data protection."
          ],
          "criteria": [],
          "criteriaDetails": [],
          "stakeholders": [],
          "evidence": []
        },
        {
          "id": "monitoring-and-improving",
          "slug": "method/monitoring-and-improving",
          "icon": "analytics-outline",
          "title": "Monitoring & Improvement",
          "description": "Monitor usage, reliability, data quality, consumer outcomes, operational cost, and reuse opportunities after release.",
          "whyItMatters": "Capabilities need continuous feedback to stay reliable, valuable, cost-effective, and reusable as consumers, systems, data, and platforms change.",
          "applyInWork": "Use metrics, analytics, and engagement practices to improve the capability over time.",
          "group": "Capability Lifecycle Core Stations",
          "lifecycleStage": "improving",
          "outcomes": [
            "Measured capability health and value",
            "Improvement backlog informed by operational and consumer feedback",
            "Reuse, reliability, data quality, and cost signals available to owners",
            "Continuous improvement aligned with consumer needs"
          ],
          "steps": [
            {
              "text": "Use metrics and analytics guidance to define capability usage, reliability, data quality, cost, adoption, and consumer-value measures.",
              "resourceId": "api-metrics-and-analytics",
              "resourceTitle": "API Metrics And Analytics",
              "canvasId": null
            },
            {
              "text": "Analyze usage metrics and incorporate consumer feedback into capability iterations.",
              "resourceId": "api-community-engagement-strategies",
              "resourceTitle": "API Community Engagement Strategies",
              "canvasId": null
            },
            {
              "text": "Establish a habit of reviewing metrics and planning continuous improvement activities.",
              "resourceId": "apiops-CI-CD-for-apis",
              "resourceTitle": "APIOps CI/CD For APIs",
              "canvasId": null
            }
          ],
          "questions": [
            "Use metrics and analytics guidance to define capability usage, reliability, data quality, cost, adoption, and consumer-value measures.",
            "Analyze usage metrics and incorporate consumer feedback into capability iterations.",
            "Establish a habit of reviewing metrics and planning continuous improvement activities.",
            "Use metrics, analytics, and engagement practices to improve the capability over time.",
            "Capabilities need continuous feedback to stay reliable, valuable, cost-effective, and reusable as consumers, systems, data, and platforms change."
          ],
          "criteria": [
            "api-documentation-ready",
            "consumer-support-ready",
            "legal-compliance-clear"
          ],
          "criteriaDetails": [
            {
              "id": "api-documentation-ready",
              "title": "Consumer-facing documentation and onboarding materials are ready.",
              "description": "Consumer-facing API documentation is complete enough for publishing and onboarding."
            },
            {
              "id": "consumer-support-ready",
              "title": "Consumer onboarding, support, and communication processes are ready.",
              "description": "Registration, support, and communication processes are ready for API consumers."
            },
            {
              "id": "legal-compliance-clear",
              "title": "Legal, privacy, and compliance requirements for publishing or release are defined and understood.",
              "description": "Legal, privacy, and compliance requirements for publishing are defined and understood."
            }
          ],
          "stakeholders": [
            {
              "id": "api-product-owner",
              "sourceKey": "api-product-owner",
              "sourceStakeholderId": "api-product-owner",
              "title": "API Product Owner",
              "description": "Drives the API opportunity, prioritization, and product-level decisions across the lifecycle.",
              "involvement": "lead",
              "responsibilities": []
            },
            {
              "id": "automation-owner",
              "sourceKey": "automation-owner",
              "sourceStakeholderId": "automation-owner",
              "title": "Automation Owner",
              "description": "Owns automation goals, business value, priorities, controls, and lifecycle outcomes.",
              "involvement": "lead",
              "responsibilities": []
            },
            {
              "id": "capability-owner",
              "sourceKey": "capability-owner",
              "sourceStakeholderId": "capability-owner",
              "title": "Capability Owner",
              "description": "Owns the capability vision, value, priorities, lifecycle, and reuse across consumers.",
              "involvement": "lead",
              "responsibilities": []
            },
            {
              "id": "integration-architect",
              "sourceKey": "integration-architect",
              "sourceStakeholderId": "integration-architect",
              "title": "Integration Architect",
              "description": "Designs integration approaches and implementation styles that connect the capability or API with other systems.",
              "involvement": "lead",
              "responsibilities": []
            },
            {
              "id": "api-consumer-specialist",
              "sourceKey": "api-consumer-specialist",
              "sourceStakeholderId": "api-consumer-specialist",
              "title": "API Consumer Representative",
              "description": "Represents the needs of developers, integrators, or other API consumers who use the API directly.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "automation-engineer",
              "sourceKey": "automation-engineer",
              "sourceStakeholderId": "automation-engineer",
              "title": "Automation Engineer",
              "description": "Implements, tests, integrates, and maintains automation solutions and supporting workflows.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "business-owner",
              "sourceKey": "business-owner",
              "sourceStakeholderId": "business-owner",
              "title": "Business Owner",
              "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "api-engineer",
              "sourceKey": "api-engineer",
              "sourceStakeholderId": "api-engineer",
              "title": "Delivery Engineer",
              "description": "Owns implementation, automation, testing, and release flow concerns needed to deliver the capability, API, or automation reliably.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "api-devrel-specialist",
              "sourceKey": "api-devrel-specialist",
              "sourceStakeholderId": "api-devrel-specialist",
              "title": "Documentation and DevRel Owner",
              "description": "Owns onboarding content, developer communication, and documentation quality for API consumers.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "platform-owner",
              "sourceKey": "platform-owner",
              "sourceStakeholderId": "platform-owner",
              "title": "Platform Owner",
              "description": "Owns platform capabilities, roadmap, operational model, and service expectations.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "process-owner",
              "sourceKey": "process-owner",
              "sourceStakeholderId": "process-owner",
              "title": "Process Owner",
              "description": "Owns the business process being automated, including objectives, rules, outcomes, and improvement priorities.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "operations-specialist",
              "sourceKey": "operations-specialist",
              "sourceStakeholderId": "operations-specialist",
              "title": "Support and Operations Owner",
              "description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
              "involvement": "core",
              "responsibilities": []
            },
            {
              "id": "compliance-specialist",
              "sourceKey": "compliance-specialist",
              "sourceStakeholderId": "compliance-specialist",
              "title": "Compliance and Legal Specialist",
              "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
              "involvement": "consulted",
              "responsibilities": []
            },
            {
              "id": "domain-specialist",
              "sourceKey": "domain-specialist",
              "sourceStakeholderId": "domain-specialist",
              "title": "Domain Expert",
              "description": "Brings deep knowledge of the business domain, concepts, rules, and constraints the capability or interface must reflect.",
              "involvement": "consulted",
              "responsibilities": []
            },
            {
              "id": "platform-architect",
              "sourceKey": "platform-architect",
              "sourceStakeholderId": "platform-architect",
              "title": "Platform Architect",
              "description": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
              "involvement": "consulted",
              "responsibilities": []
            },
            {
              "id": "security-specialist",
              "sourceKey": "security-specialist",
              "sourceStakeholderId": "security-specialist",
              "title": "Security Specialist",
              "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
              "involvement": "consulted",
              "responsibilities": []
            }
          ],
          "evidence": [
            "metrics",
            "consumer-feedback",
            "incident-report",
            "roadmap"
          ]
        },
        {
          "id": "security-and-privacy",
          "slug": "method/security-and-privacy",
          "icon": "cloud-lock-outline",
          "title": "Security and Privacy - Protect Your APIs and Users",
          "description": "Implement security and privacy measures to protect APIs and user data from threats and breaches.",
          "whyItMatters": "APIs are vulnerable to security threats and data breaches. This station provides guidelines for implementing security and privacy measures that protect APIs and user data, ensuring trust and compliance.",
          "applyInWork": "Provide security frameworks, tools, and best practices for API security and privacy. Ensure teams implement security measures throughout the API lifecycle, from design to publishing and monitoring.",
          "group": "Supporting Stations",
          "lifecycleStage": "supporting",
          "outcomes": [
            "APIs secured against threats and vulnerabilities",
            "User data protected through privacy measures",
            "Security best practices implemented in API design and development",
            "Compliance with security standards and regulations"
          ],
          "steps": [
            {
              "text": "Implement security measures such as authentication, authorization, encryption, and rate limiting to protect APIs from threats.",
              "resourceId": "api-security-best-practices",
              "resourceTitle": "API Security Best Practices",
              "canvasId": null
            },
            {
              "text": "Ensure user data privacy by implementing data protection measures, such as anonymization and access controls.",
              "resourceId": "data-privacy-guidelines",
              "resourceTitle": "Data Privacy Guidelines",
              "canvasId": null
            },
            {
              "text": "Conduct regular security audits and vulnerability assessments to identify and mitigate risks.",
              "resourceId": "",
              "resourceTitle": "",
              "canvasId": null
            }
          ],
          "questions": [
            "Implement security measures such as authentication, authorization, encryption, and rate limiting to protect APIs from threats.",
            "Ensure user data privacy by implementing data protection measures, such as anonymization and access controls.",
            "Conduct regular security audits and vulnerability assessments to identify and mitigate risks.",
            "Provide security frameworks, tools, and best practices for API security and privacy. Ensure teams implement security measures throughout the API lifecycle, from design to publishing and monitoring.",
            "APIs are vulnerable to security threats and data breaches. This station provides guidelines for implementing security and privacy measures that protect APIs and user data, ensuring trust and compliance."
          ],
          "criteria": [],
          "criteriaDetails": [],
          "stakeholders": [],
          "evidence": []
        },
        {
          "id": "design-standards",
          "slug": "method/design-standards",
          "icon": "design-services-outline",
          "title": "Design Standards - Ensure Consistent and High-Quality API Design",
          "description": "Establish design standards and guidelines to ensure consistent and high-quality API design across the organization.",
          "whyItMatters": "Consistent and high-quality API design is essential for usability, maintainability, and scalability. This station provides design standards and guidelines that help teams create APIs that are easy to use, understand, and maintain.",
          "applyInWork": "Provide design standards documentation, reusable components, and design review processes. Ensure teams follow design standards and conduct regular reviews to maintain high-quality API design.",
          "group": "Supporting Stations",
          "lifecycleStage": "supporting",
          "outcomes": [
            "Consistent API design across the organization",
            "High-quality APIs that meet user needs",
            "Reusable design patterns and components",
            "Reduced design inconsistencies and technical debt"
          ],
          "steps": [
            {
              "text": "Define design standards and guidelines for API design, including naming conventions, response formats, and error handling.",
              "resourceId": "api-design-principles",
              "resourceTitle": "API Design Principles",
              "canvasId": null
            },
            {
              "text": "Create reusable design patterns and components that teams can leverage to ensure consistency and quality.",
              "resourceId": "",
              "resourceTitle": "",
              "canvasId": null
            },
            {
              "text": "Conduct design reviews and audits to ensure adherence to design standards and identify areas for improvement.",
              "resourceId": "api-audit-checklist",
              "resourceTitle": "API Audit Checklist",
              "canvasId": null
            }
          ],
          "questions": [
            "Define design standards and guidelines for API design, including naming conventions, response formats, and error handling.",
            "Create reusable design patterns and components that teams can leverage to ensure consistency and quality.",
            "Conduct design reviews and audits to ensure adherence to design standards and identify areas for improvement.",
            "Provide design standards documentation, reusable components, and design review processes. Ensure teams follow design standards and conduct regular reviews to maintain high-quality API design.",
            "Consistent and high-quality API design is essential for usability, maintainability, and scalability. This station provides design standards and guidelines that help teams create APIs that are easy to use, understand, and maintain."
          ],
          "criteria": [],
          "criteriaDetails": [],
          "stakeholders": [],
          "evidence": []
        },
        {
          "id": "vendor-management",
          "slug": "method/vendor-management",
          "icon": "handshake-outline",
          "title": "Vendor Management - Manage Third-Party API Integrations",
          "description": "Effectively manage third-party API vendors and integrations to ensure reliability and compliance.",
          "whyItMatters": "Third-party APIs can introduce risks and dependencies that impact your API ecosystem. This station provides guidelines for managing vendor relationships, ensuring reliability, compliance, and alignment with your API strategy.",
          "applyInWork": "Provide vendor management frameworks, evaluation criteria, and monitoring tools. Ensure teams effectively manage third-party API vendors, ensuring reliability, compliance, and alignment with organizational standards.",
          "group": "Supporting Stations",
          "lifecycleStage": "supporting",
          "outcomes": [
            "Effective vendor management processes established",
            "Third-party APIs integrated reliably and securely",
            "Vendor compliance with organizational standards",
            "Reduced risks associated with third-party dependencies"
          ],
          "steps": [
            {
              "text": "Establish vendor management processes to evaluate, onboard, and monitor third-party API vendors.",
              "resourceId": "vendor-management-best-practices",
              "resourceTitle": "Vendor Management Best Practices",
              "canvasId": null
            },
            {
              "text": "Define criteria for evaluating vendor APIs, including reliability, security, and compliance.",
              "resourceId": "vendor-management-best-practices",
              "resourceTitle": "Vendor Management Best Practices",
              "canvasId": null
            },
            {
              "text": "Monitor vendor performance and compliance with service level agreements (SLAs) and organizational standards.",
              "resourceId": "vendor-management-best-practices",
              "resourceTitle": "Vendor Management Best Practices",
              "canvasId": null
            }
          ],
          "questions": [
            "Establish vendor management processes to evaluate, onboard, and monitor third-party API vendors.",
            "Define criteria for evaluating vendor APIs, including reliability, security, and compliance.",
            "Monitor vendor performance and compliance with service level agreements (SLAs) and organizational standards.",
            "Provide vendor management frameworks, evaluation criteria, and monitoring tools. Ensure teams effectively manage third-party API vendors, ensuring reliability, compliance, and alignment with organizational standards.",
            "Third-party APIs can introduce risks and dependencies that impact your API ecosystem. This station provides guidelines for managing vendor relationships, ensuring reliability, compliance, and alignment with your API strategy."
          ],
          "criteria": [],
          "criteriaDetails": [],
          "stakeholders": [],
          "evidence": []
        },
        {
          "id": "contract-design",
          "slug": "method/contract-design",
          "icon": "folder-code-outline",
          "title": "Contract Design - Define Clear API Contracts",
          "description": "Create clear and well-defined API contracts that outline expectations, responsibilities, and usage guidelines.",
          "whyItMatters": "API contracts are essential for ensuring clarity and alignment between API providers and consumers. This station provides guidelines for designing API contracts that are clear, comprehensive, and easy to understand.",
          "applyInWork": "Provide contract design templates, standardized formats, and review processes. Ensure teams create clear and well-defined API contracts that outline expectations, responsibilities, and usage guidelines.",
          "group": "Supporting Stations",
          "lifecycleStage": "supporting",
          "outcomes": [
            "Clear API contracts defined for each API",
            "Expectations and responsibilities outlined for API providers and consumers",
            "Usage guidelines and best practices documented",
            "Reduced misunderstandings and disputes over API usage"
          ],
          "steps": [
            {
              "text": "Define API contracts that outline the expectations, responsibilities, and usage guidelines for each API.",
              "resourceId": "contract-first-design",
              "resourceTitle": "Contract First Design",
              "canvasId": null
            },
            {
              "text": "Use standardized formats (e.g., OpenAPI, AsyncAPI) to create machine-readable API contracts that are easy to share and validate.",
              "resourceId": "contract-first-design",
              "resourceTitle": "Contract First Design",
              "canvasId": null
            },
            {
              "text": "Ensure API contracts are reviewed and approved by stakeholders to ensure alignment and clarity.",
              "resourceId": "api-audit-checklist",
              "resourceTitle": "API Audit Checklist",
              "canvasId": null
            }
          ],
          "questions": [
            "Define API contracts that outline the expectations, responsibilities, and usage guidelines for each API.",
            "Use standardized formats (e.g., OpenAPI, AsyncAPI) to create machine-readable API contracts that are easy to share and validate.",
            "Ensure API contracts are reviewed and approved by stakeholders to ensure alignment and clarity.",
            "Provide contract design templates, standardized formats, and review processes. Ensure teams create clear and well-defined API contracts that outline expectations, responsibilities, and usage guidelines.",
            "API contracts are essential for ensuring clarity and alignment between API providers and consumers. This station provides guidelines for designing API contracts that are clear, comprehensive, and easy to understand."
          ],
          "criteria": [],
          "criteriaDetails": [],
          "stakeholders": [],
          "evidence": []
        },
        {
          "id": "development",
          "slug": "method/development",
          "icon": "deployed-code-outline",
          "title": "Development - Build APIs with Best Practices",
          "description": "Implement APIs using best practices and frameworks to ensure quality, maintainability, and scalability.",
          "whyItMatters": "API development is a critical phase that determines the quality and reliability of the API. This station provides best practices and frameworks for API development, ensuring APIs are built to high standards and can be maintained and scaled effectively.",
          "applyInWork": "Provide development frameworks, libraries, and coding standards for API implementation. Ensure teams follow best practices and conduct code reviews to maintain high-quality API development.",
          "group": "Supporting Stations",
          "lifecycleStage": "supporting",
          "outcomes": [
            "APIs developed using best practices and frameworks",
            "High-quality, maintainable, and scalable APIs",
            "Consistent coding standards and practices followed",
            "Reduced development time and technical debt"
          ],
          "steps": [
            {
              "text": "Use established frameworks and libraries to implement APIs, ensuring they are reusable and maintainable.",
              "resourceId": "api-development-best-practices",
              "resourceTitle": "API Development Best Practices",
              "canvasId": null
            },
            {
              "text": "Apply contract-first or design-first approaches to ensure API contracts are validated before implementation.",
              "resourceId": "contract-first-design",
              "resourceTitle": "Contract First Design",
              "canvasId": null
            },
            {
              "text": "Follow coding standards and best practices to ensure consistent and high-quality API development.",
              "resourceId": "api-development-best-practices",
              "resourceTitle": "API Development Best Practices",
              "canvasId": null
            }
          ],
          "questions": [
            "Use established frameworks and libraries to implement APIs, ensuring they are reusable and maintainable.",
            "Apply contract-first or design-first approaches to ensure API contracts are validated before implementation.",
            "Follow coding standards and best practices to ensure consistent and high-quality API development.",
            "Provide development frameworks, libraries, and coding standards for API implementation. Ensure teams follow best practices and conduct code reviews to maintain high-quality API development.",
            "API development is a critical phase that determines the quality and reliability of the API. This station provides best practices and frameworks for API development, ensuring APIs are built to high standards and can be maintained and scaled effectively."
          ],
          "criteria": [],
          "criteriaDetails": [],
          "stakeholders": [],
          "evidence": []
        },
        {
          "id": "ci-cd",
          "slug": "method/ci-cd",
          "icon": "deployed-code-update-outline",
          "title": "CI/CD - Automate API Delivery",
          "description": "Implement continuous integration and continuous delivery (CI/CD) pipelines to automate API delivery and ensure consistent quality.",
          "whyItMatters": "CI/CD is essential for ensuring that APIs are delivered quickly, reliably, and with high quality. This station provides guidelines for implementing CI/CD pipelines that automate the build, test, and deployment processes for APIs.",
          "applyInWork": "Provide CI/CD frameworks, tools, and best practices for API delivery. Ensure teams implement automated pipelines that support continuous integration, testing, and deployment of APIs.",
          "group": "Supporting Stations",
          "lifecycleStage": "supporting",
          "outcomes": [
            "Automated CI/CD pipelines established for API delivery",
            "Consistent quality and traceability in API delivery",
            "Faster iterations and reduced time to market",
            "Improved collaboration and feedback loops in API development"
          ],
          "steps": [
            {
              "text": "Use CI/CD pipelines to automate build, test, and deployment processes, ensuring consistent quality and traceability.",
              "resourceId": "apiops-CI-CD-for-apis",
              "resourceTitle": "APIOps CI/CD For APIs",
              "canvasId": null
            },
            {
              "text": "Integrate functional and non-functional testing into the CI/CD pipeline to ensure APIs meet quality standards.",
              "resourceId": "api-testing-best-practices",
              "resourceTitle": "API Testing Best Practices",
              "canvasId": null
            },
            {
              "text": "Implement automated security checks and compliance validations in the CI/CD pipeline to ensure APIs are secure and compliant.",
              "resourceId": "api-security-best-practices",
              "resourceTitle": "API Security Best Practices",
              "canvasId": null
            }
          ],
          "questions": [
            "Use CI/CD pipelines to automate build, test, and deployment processes, ensuring consistent quality and traceability.",
            "Integrate functional and non-functional testing into the CI/CD pipeline to ensure APIs meet quality standards.",
            "Implement automated security checks and compliance validations in the CI/CD pipeline to ensure APIs are secure and compliant.",
            "Provide CI/CD frameworks, tools, and best practices for API delivery. Ensure teams implement automated pipelines that support continuous integration, testing, and deployment of APIs.",
            "CI/CD is essential for ensuring that APIs are delivered quickly, reliably, and with high quality. This station provides guidelines for implementing CI/CD pipelines that automate the build, test, and deployment processes for APIs."
          ],
          "criteria": [],
          "criteriaDetails": [],
          "stakeholders": [],
          "evidence": []
        },
        {
          "id": "test-automation",
          "slug": "method/test-automation",
          "icon": "deployed-code-alert-outline",
          "title": "Test Automation - Ensure API Quality",
          "description": "Implement automated testing practices to ensure API quality, reliability, and performance.",
          "whyItMatters": "Automated testing is crucial for ensuring that APIs function correctly and meet quality standards. This station provides guidelines for implementing automated testing practices that cover functional, security, and performance testing for APIs.",
          "applyInWork": "Provide test automation frameworks, tools, and best practices for API testing. Ensure teams implement automated tests that cover functional, security, and performance aspects of APIs.",
          "group": "Supporting Stations",
          "lifecycleStage": "supporting",
          "outcomes": [
            "Automated testing practices implemented for APIs",
            "Functional, security, and performance tests automated",
            "Reduced manual testing effort and increased test coverage",
            "Improved API reliability and quality"
          ],
          "steps": [
            {
              "text": "Use automated testing tools to validate API functionality, security, and performance.",
              "resourceId": "api-testing-best-practices",
              "resourceTitle": "API Testing Best Practices",
              "canvasId": null
            },
            {
              "text": "Implement test automation frameworks that support contract testing, integration testing, and end-to-end testing.",
              "resourceId": "api-testing-best-practices",
              "resourceTitle": "API Testing Best Practices",
              "canvasId": null
            },
            {
              "text": "Integrate automated tests into the CI/CD pipeline to ensure continuous validation of API quality.",
              "resourceId": "apiops-CI-CD-for-apis",
              "resourceTitle": "APIOps CI/CD For APIs",
              "canvasId": null
            }
          ],
          "questions": [
            "Use automated testing tools to validate API functionality, security, and performance.",
            "Implement test automation frameworks that support contract testing, integration testing, and end-to-end testing.",
            "Integrate automated tests into the CI/CD pipeline to ensure continuous validation of API quality.",
            "Provide test automation frameworks, tools, and best practices for API testing. Ensure teams implement automated tests that cover functional, security, and performance aspects of APIs.",
            "Automated testing is crucial for ensuring that APIs function correctly and meet quality standards. This station provides guidelines for implementing automated testing practices that cover functional, security, and performance testing for APIs."
          ],
          "criteria": [],
          "criteriaDetails": [],
          "stakeholders": [],
          "evidence": []
        },
        {
          "id": "release-management",
          "slug": "method/release-management",
          "icon": "rocket-launch-outline",
          "title": "Release Management - Manage API Releases Effectively",
          "description": "Implement release management practices to ensure smooth and controlled API releases.",
          "whyItMatters": "Effective release management is essential for ensuring that API releases are smooth, controlled, and aligned with business needs. This station provides guidelines for managing API releases, including versioning, deployment strategies, and rollback procedures.",
          "applyInWork": "Provide release management frameworks, versioning guidelines, and deployment strategies. Ensure teams follow best practices for managing API releases, including versioning, deployment, and rollback procedures.",
          "group": "Supporting Stations",
          "lifecycleStage": "supporting",
          "outcomes": [
            "Controlled and smooth API releases",
            "Versioning and deployment strategies defined",
            "Rollback procedures established for API releases",
            "Reduced risks associated with API changes"
          ],
          "steps": [
            {
              "text": "Define versioning strategies for APIs to manage changes and ensure backward compatibility.",
              "resourceId": "api-versioning-best-practices",
              "resourceTitle": "API Versioning Best Practices",
              "canvasId": null
            },
            {
              "text": "Implement deployment strategies (e.g., blue-green deployments, canary releases) to minimize risks during API releases.",
              "resourceId": "apiops-CI-CD-for-apis",
              "resourceTitle": "APIOps CI/CD For APIs",
              "canvasId": null
            },
            {
              "text": "Establish rollback procedures to quickly revert changes in case of issues during API releases.",
              "resourceId": "",
              "resourceTitle": "",
              "canvasId": null
            }
          ],
          "questions": [
            "Define versioning strategies for APIs to manage changes and ensure backward compatibility.",
            "Implement deployment strategies (e.g., blue-green deployments, canary releases) to minimize risks during API releases.",
            "Establish rollback procedures to quickly revert changes in case of issues during API releases.",
            "Provide release management frameworks, versioning guidelines, and deployment strategies. Ensure teams follow best practices for managing API releases, including versioning, deployment, and rollback procedures.",
            "Effective release management is essential for ensuring that API releases are smooth, controlled, and aligned with business needs. This station provides guidelines for managing API releases, including versioning, deployment strategies, and rollback procedures."
          ],
          "criteria": [],
          "criteriaDetails": [],
          "stakeholders": [],
          "evidence": []
        },
        {
          "id": "service-agreements",
          "slug": "method/service-agreements",
          "icon": "contract-outline",
          "title": "Service Agreements - Define API Service Levels",
          "description": "Establish service agreements that define expectations, service levels, and responsibilities for API providers and consumers.",
          "whyItMatters": "Service agreements are essential for ensuring clarity and alignment between API providers and consumers. This station provides guidelines for creating service agreements that outline expectations, service levels, and responsibilities, reducing misunderstandings and disputes.",
          "applyInWork": "Provide service agreement templates, standardized formats, and review processes. Ensure teams create clear and well-defined service agreements that outline expectations, service levels, and responsibilities for API providers and consumers.",
          "group": "Supporting Stations",
          "lifecycleStage": "supporting",
          "outcomes": [
            "Clear service agreements defined for each API",
            "Expectations and service levels outlined for API providers and consumers",
            "Responsibilities and support processes documented",
            "Improved communication and collaboration between API teams"
          ],
          "steps": [
            {
              "text": "Define service agreements that outline the expectations, service levels, and responsibilities for each API.",
              "resourceId": "service-agreement-template",
              "resourceTitle": "Service Agreement Template",
              "canvasId": null
            },
            {
              "text": "Use standardized formats to create machine-readable service agreements that are easy to share and validate.",
              "resourceId": "service-agreement-template",
              "resourceTitle": "Service Agreement Template",
              "canvasId": null
            },
            {
              "text": "Ensure service agreements are reviewed and approved by stakeholders to ensure alignment and clarity.",
              "resourceId": "service-agreement-template",
              "resourceTitle": "Service Agreement Template",
              "canvasId": null
            }
          ],
          "questions": [
            "Define service agreements that outline the expectations, service levels, and responsibilities for each API.",
            "Use standardized formats to create machine-readable service agreements that are easy to share and validate.",
            "Ensure service agreements are reviewed and approved by stakeholders to ensure alignment and clarity.",
            "Provide service agreement templates, standardized formats, and review processes. Ensure teams create clear and well-defined service agreements that outline expectations, service levels, and responsibilities for API providers and consumers.",
            "Service agreements are essential for ensuring clarity and alignment between API providers and consumers. This station provides guidelines for creating service agreements that outline expectations, service levels, and responsibilities, reducing misunderstandings and disputes."
          ],
          "criteria": [],
          "criteriaDetails": [],
          "stakeholders": [],
          "evidence": []
        },
        {
          "id": "api-consumer-adoption",
          "slug": "method/api-consumer-adoption",
          "icon": "chart-data-outline",
          "title": "Consumer Adoption",
          "description": "Implement strategies to drive consumer adoption and engagement so reusable capabilities are used effectively.",
          "whyItMatters": "Driving consumer adoption is crucial for realizing the value of reusable capabilities. This station provides strategies and best practices for engaging consumers, helping them understand how to use capabilities effectively and derive value from them.",
          "applyInWork": "Provide onboarding resources, educational materials, and engagement strategies for consumers. Ensure teams implement adoption practices that improve engagement, satisfaction, and reuse.",
          "group": "Supporting Stations",
          "lifecycleStage": "supporting",
          "outcomes": [
            "Consumer adoption strategies implemented",
            "Increased usage and engagement",
            "Consumers educated on capability features and benefits",
            "Improved consumer satisfaction and loyalty"
          ],
          "steps": [
            {
              "text": "Develop onboarding processes and resources to help consumers understand how to use reusable capabilities effectively.",
              "resourceId": "api-onboarding-best-practices",
              "resourceTitle": "API Onboarding Best Practices",
              "canvasId": null
            },
            {
              "text": "Create educational materials that explain capability features, benefits, and usage patterns.",
              "resourceId": "api-community-engagement-strategies",
              "resourceTitle": "API Community Engagement Strategies",
              "canvasId": null
            },
            {
              "text": "Engage with consumers through feedback loops, support channels, and communities to understand needs and improve adoption.",
              "resourceId": "api-community-engagement-strategies",
              "resourceTitle": "API Community Engagement Strategies",
              "canvasId": null
            }
          ],
          "questions": [
            "Develop onboarding processes and resources to help consumers understand how to use reusable capabilities effectively.",
            "Create educational materials that explain capability features, benefits, and usage patterns.",
            "Engage with consumers through feedback loops, support channels, and communities to understand needs and improve adoption.",
            "Provide onboarding resources, educational materials, and engagement strategies for consumers. Ensure teams implement adoption practices that improve engagement, satisfaction, and reuse.",
            "Driving consumer adoption is crucial for realizing the value of reusable capabilities. This station provides strategies and best practices for engaging consumers, helping them understand how to use capabilities effectively and derive value from them."
          ],
          "criteria": [],
          "criteriaDetails": [],
          "stakeholders": [],
          "evidence": []
        },
        {
          "id": "api-promotion",
          "slug": "method/api-promotion",
          "icon": "brand-awareness-outline",
          "title": "Promotion",
          "description": "Promote reusable capabilities to increase visibility, usage, and adoption among target audiences.",
          "whyItMatters": "Promotion increases visibility and drives usage. This station provides strategies and best practices for making target audiences aware of reusable capabilities and their value.",
          "applyInWork": "Provide communication strategies, promotional materials, and community engagement resources. Ensure teams implement promotion practices that increase visibility, usage, and adoption among target audiences.",
          "group": "Supporting Stations",
          "lifecycleStage": "supporting",
          "outcomes": [
            "Promotion strategies implemented",
            "Increased visibility and awareness",
            "Higher usage and adoption rates",
            "Improved consumer engagement and satisfaction"
          ],
          "steps": [
            {
              "text": "Develop communication strategies to promote reusable capabilities to target audiences, including internal channels, communities, demos, and enablement events.",
              "resourceId": "api-community-engagement-strategies",
              "resourceTitle": "API Community Engagement Strategies",
              "canvasId": null
            },
            {
              "text": "Create promotional materials such as use cases, success stories, and release notes that highlight value and benefits.",
              "resourceId": "api-community-engagement-strategies",
              "resourceTitle": "API Community Engagement Strategies",
              "canvasId": null
            },
            {
              "text": "Engage with relevant communities and forums to share updates, gather feedback, and promote usage.",
              "resourceId": "api-community-engagement-strategies",
              "resourceTitle": "API Community Engagement Strategies",
              "canvasId": null
            }
          ],
          "questions": [
            "Develop communication strategies to promote reusable capabilities to target audiences, including internal channels, communities, demos, and enablement events.",
            "Create promotional materials such as use cases, success stories, and release notes that highlight value and benefits.",
            "Engage with relevant communities and forums to share updates, gather feedback, and promote usage.",
            "Provide communication strategies, promotional materials, and community engagement resources. Ensure teams implement promotion practices that increase visibility, usage, and adoption among target audiences.",
            "Promotion increases visibility and drives usage. This station provides strategies and best practices for making target audiences aware of reusable capabilities and their value."
          ],
          "criteria": [],
          "criteriaDetails": [],
          "stakeholders": [],
          "evidence": []
        },
        {
          "id": "partner-integration",
          "slug": "method/partner-integration",
          "icon": "integration-instructions-outline",
          "title": "Partner Integration - Collaborate with Partners",
          "description": "Facilitate partner integrations to enhance API capabilities and expand reach.",
          "whyItMatters": "Partner integrations can enhance API capabilities and expand reach. This station provides guidelines for collaborating with partners to integrate their APIs, ensuring seamless interoperability and value creation.",
          "applyInWork": "Provide partner integration frameworks, guidelines, and monitoring tools. Ensure teams effectively collaborate with partners to enhance API capabilities, expand reach, and drive innovation.",
          "group": "Supporting Stations",
          "lifecycleStage": "supporting",
          "outcomes": [
            "Partner integration processes established",
            "Enhanced API capabilities through partner APIs",
            "Expanded reach and market opportunities through partnerships",
            "Improved collaboration and innovation with partners"
          ],
          "steps": [
            {
              "text": "Identify potential partners whose APIs can enhance your API capabilities and value proposition.",
              "resourceId": "ecosystem-vision-template",
              "resourceTitle": "Ecosystem Vision Template",
              "canvasId": null
            },
            {
              "text": "Establish integration processes and guidelines for collaborating with partners, including technical integration, data sharing, and support.",
              "resourceId": "partner-integration-guidelines",
              "resourceTitle": "Partner Integration Guidelines",
              "canvasId": null
            },
            {
              "text": "Monitor partner API performance and compliance to ensure reliability and alignment with your API strategy.",
              "resourceId": "partner-integration-guidelines",
              "resourceTitle": "Partner Integration Guidelines",
              "canvasId": null
            }
          ],
          "questions": [
            "Identify potential partners whose APIs can enhance your API capabilities and value proposition.",
            "Establish integration processes and guidelines for collaborating with partners, including technical integration, data sharing, and support.",
            "Monitor partner API performance and compliance to ensure reliability and alignment with your API strategy.",
            "Provide partner integration frameworks, guidelines, and monitoring tools. Ensure teams effectively collaborate with partners to enhance API capabilities, expand reach, and drive innovation.",
            "Partner integrations can enhance API capabilities and expand reach. This station provides guidelines for collaborating with partners to integrate their APIs, ensuring seamless interoperability and value creation."
          ],
          "criteria": [],
          "criteriaDetails": [],
          "stakeholders": [],
          "evidence": []
        },
        {
          "id": "api-mindset",
          "slug": "method/api-mindset",
          "icon": "psychology-outline",
          "title": "API Mindset - Foster an API-First Culture",
          "description": "Cultivate an API-first mindset across the organization to drive innovation and collaboration.",
          "whyItMatters": "An API-first mindset is essential for fostering innovation and collaboration across the organization. This station provides strategies for cultivating an API-first culture, ensuring that APIs are seen as strategic assets that drive business value.",
          "applyInWork": "Provide training programs, resources, and communication strategies to foster an API-first culture. Ensure teams understand the value of APIs and are empowered to drive API strategy and initiatives.",
          "group": "Supporting Stations",
          "lifecycleStage": "supporting",
          "outcomes": [
            "API-first culture established across the organization",
            "Increased innovation and collaboration through APIs",
            "API teams empowered to drive API strategy and initiatives",
            "Improved alignment between business goals and API development"
          ],
          "steps": [
            {
              "text": "Promote the value of APIs as strategic assets that drive business value and innovation.",
              "resourceId": "ecosystem-vision-template",
              "resourceTitle": "Ecosystem Vision Template",
              "canvasId": null
            },
            {
              "text": "Encourage cross-functional collaboration between API teams, business units, and stakeholders to align API initiatives with business goals.",
              "resourceId": "cross-functional-collaboration-best-practices",
              "resourceTitle": "Cross Functional Collaboration Best Practices",
              "canvasId": null
            },
            {
              "text": "Provide training and resources to help teams adopt an API-first mindset  and understand the benefits of APIs.",
              "resourceId": "api-training-programs",
              "resourceTitle": "API Training Programs",
              "canvasId": null
            }
          ],
          "questions": [
            "Promote the value of APIs as strategic assets that drive business value and innovation.",
            "Encourage cross-functional collaboration between API teams, business units, and stakeholders to align API initiatives with business goals.",
            "Provide training and resources to help teams adopt an API-first mindset  and understand the benefits of APIs.",
            "Provide training programs, resources, and communication strategies to foster an API-first culture. Ensure teams understand the value of APIs and are empowered to drive API strategy and initiatives.",
            "An API-first mindset is essential for fostering innovation and collaboration across the organization. This station provides strategies for cultivating an API-first culture, ensuring that APIs are seen as strategic assets that drive business value."
          ],
          "criteria": [],
          "criteriaDetails": [],
          "stakeholders": [],
          "evidence": []
        },
        {
          "id": "roles-and-responsibilities",
          "slug": "method/roles-and-responsibilities",
          "icon": "manage-accounts-outline",
          "title": "Roles and Responsibilities - Define API Team Structures",
          "description": "Define clear roles and responsibilities for API teams to ensure effective collaboration and accountability.",
          "whyItMatters": "Clear roles and responsibilities are essential for effective collaboration and accountability within API teams. This station provides guidelines for defining team structures, roles, and responsibilities, ensuring that everyone understands their contributions to API initiatives.",
          "applyInWork": "Provide team structure guidelines, role definitions, and communication strategies. Ensure teams have clear roles and responsibilities that promote effective collaboration and accountability in API initiatives.",
          "group": "Supporting Stations",
          "lifecycleStage": "supporting",
          "outcomes": [
            "Clear roles and responsibilities defined for API teams",
            "Effective collaboration and accountability within API teams",
            "Improved communication and alignment between team members",
            "Reduced confusion and overlap in responsibilities"
          ],
          "steps": [
            {
              "text": "Define team structures and roles for API teams, including API product owners, developers, architects, and operations.",
              "resourceId": "api-team-structure-guidelines",
              "resourceTitle": "API Team Structure Guidelines",
              "canvasId": null
            },
            {
              "text": "Establish clear responsibilities for each role, including API design, development, testing, and operations.",
              "resourceId": "role-communication-best-practices",
              "resourceTitle": "Role Communication Best Practices",
              "canvasId": null
            },
            {
              "text": "Ensure roles and responsibilities are communicated to all team members and stakeholders to ensure alignment.",
              "resourceId": "role-communication-best-practices",
              "resourceTitle": "Role Communication Best Practices",
              "canvasId": null
            }
          ],
          "questions": [
            "Define team structures and roles for API teams, including API product owners, developers, architects, and operations.",
            "Establish clear responsibilities for each role, including API design, development, testing, and operations.",
            "Ensure roles and responsibilities are communicated to all team members and stakeholders to ensure alignment.",
            "Provide team structure guidelines, role definitions, and communication strategies. Ensure teams have clear roles and responsibilities that promote effective collaboration and accountability in API initiatives.",
            "Clear roles and responsibilities are essential for effective collaboration and accountability within API teams. This station provides guidelines for defining team structures, roles, and responsibilities, ensuring that everyone understands their contributions to API initiatives."
          ],
          "criteria": [],
          "criteriaDetails": [],
          "stakeholders": [],
          "evidence": []
        },
        {
          "id": "upskilling",
          "slug": "method/upskilling",
          "icon": "school-outline",
          "title": "Upskilling - Enhance API Skills and Knowledge",
          "description": "Provide training and resources to enhance API skills and knowledge across the organization.",
          "whyItMatters": "Continuous learning and upskilling are essential for keeping API teams updated with the latest technologies, practices, and trends. This station provides training programs and resources to enhance API skills and knowledge, ensuring teams are equipped to deliver high-quality APIs.",
          "applyInWork": "Provide training programs, resources, and assessment tools to enhance API skills and knowledge. Ensure teams have access to continuous learning opportunities that empower them to drive API innovation and quality.",
          "group": "Supporting Stations",
          "lifecycleStage": "supporting",
          "outcomes": [
            "API skills and knowledge enhanced across the organization",
            "Increased proficiency in API design, development, and management",
            "Improved ability to adopt new technologies and practices",
            "Empowered teams to drive API innovation and quality"
          ],
          "steps": [
            {
              "text": "Identify key API skills and knowledge areas that need enhancement, such as API design, security, and performance.",
              "resourceId": "api-training-programs",
              "resourceTitle": "API Training Programs",
              "canvasId": null
            }
          ],
          "questions": [
            "Identify key API skills and knowledge areas that need enhancement, such as API design, security, and performance.",
            "Provide training programs, resources, and assessment tools to enhance API skills and knowledge. Ensure teams have access to continuous learning opportunities that empower them to drive API innovation and quality.",
            "Continuous learning and upskilling are essential for keeping API teams updated with the latest technologies, practices, and trends. This station provides training programs and resources to enhance API skills and knowledge, ensuring teams are equipped to deliver high-quality APIs."
          ],
          "criteria": [],
          "criteriaDetails": [],
          "stakeholders": [],
          "evidence": []
        },
        {
          "id": "operating-guidelines",
          "slug": "method/operating-guidelines",
          "icon": "list-alt-outline",
          "title": "Operating Guidelines - Establish API Governance",
          "description": "Establish operating guidelines and governance practices to ensure consistent API management and quality.",
          "whyItMatters": "Effective API governance is essential for ensuring consistent API management, quality, and compliance. This station provides operating guidelines and governance practices that help teams manage APIs effectively, ensuring they align with organizational standards and best practices.",
          "applyInWork": "Provide operating guidelines, governance frameworks, and monitoring tools for API management. Ensure teams follow established practices that promote consistent API management, quality, and compliance with organizational standards.",
          "group": "Supporting Stations",
          "lifecycleStage": "supporting",
          "outcomes": [
            "API governance practices established",
            "Consistent API management and quality across the organization",
            "Compliance with organizational standards and best practices",
            "Improved visibility and control over API initiatives"
          ],
          "steps": [
            {
              "text": "Define operating guidelines based on APIOps Cycles that outline the processes, standards, and best practices for API management.",
              "resourceId": "",
              "resourceTitle": "",
              "canvasId": null
            },
            {
              "text": "Establish governance practices that ensure APIs are managed consistently, including reviews, audits, and compliance checks.",
              "resourceId": "",
              "resourceTitle": "",
              "canvasId": null
            },
            {
              "text": "Monitor API initiatives to ensure adherence to operating guidelines and governance practices",
              "resourceId": "api-metrics-and-analytics",
              "resourceTitle": "API Metrics And Analytics",
              "canvasId": null
            }
          ],
          "questions": [
            "Define operating guidelines based on APIOps Cycles that outline the processes, standards, and best practices for API management.",
            "Establish governance practices that ensure APIs are managed consistently, including reviews, audits, and compliance checks.",
            "Monitor API initiatives to ensure adherence to operating guidelines and governance practices",
            "Provide operating guidelines, governance frameworks, and monitoring tools for API management. Ensure teams follow established practices that promote consistent API management, quality, and compliance with organizational standards.",
            "Effective API governance is essential for ensuring consistent API management, quality, and compliance. This station provides operating guidelines and governance practices that help teams manage APIs effectively, ensuring they align with organizational standards and best practices."
          ],
          "criteria": [],
          "criteriaDetails": [],
          "stakeholders": [],
          "evidence": []
        },
        {
          "id": "portfolio-management",
          "slug": "method/portfolio-management",
          "icon": "cases-outline",
          "title": "Portfolio Management - Manage API Portfolio Effectively",
          "description": "Manage the API portfolio effectively to ensure alignment with business goals and strategic initiatives.",
          "whyItMatters": "Effective API portfolio management is essential for ensuring that APIs align with business goals and strategic initiatives. This station provides guidelines for managing the API portfolio, ensuring that APIs are prioritized, monitored, and optimized to deliver maximum value.",
          "applyInWork": "Provide portfolio management frameworks, prioritization criteria, and monitoring tools for API management. Ensure teams effectively manage the API portfolio, ensuring alignment with business goals, strategic initiatives, and delivering maximum value.",
          "group": "Supporting Stations",
          "lifecycleStage": "supporting",
          "outcomes": [
            "API portfolio management practices established",
            "APIs aligned with business goals and strategic initiatives",
            "Prioritization and optimization of APIs based on value and impact",
            "Improved visibility and control over the API portfolio"
          ],
          "steps": [
            {
              "text": "Define portfolio management practices that outline the processes for managing the API portfolio, including prioritization, monitoring, and optimization.",
              "resourceId": "api-portfolio-management-guidelines",
              "resourceTitle": "API Portfolio Management Guidelines",
              "canvasId": null
            }
          ],
          "questions": [
            "Define portfolio management practices that outline the processes for managing the API portfolio, including prioritization, monitoring, and optimization.",
            "Provide portfolio management frameworks, prioritization criteria, and monitoring tools for API management. Ensure teams effectively manage the API portfolio, ensuring alignment with business goals, strategic initiatives, and delivering maximum value.",
            "Effective API portfolio management is essential for ensuring that APIs align with business goals and strategic initiatives. This station provides guidelines for managing the API portfolio, ensuring that APIs are prioritized, monitored, and optimized to deliver maximum value."
          ],
          "criteria": [],
          "criteriaDetails": [],
          "stakeholders": [],
          "evidence": []
        },
        {
          "id": "budget-and-resource-management",
          "slug": "method/budget-and-resource-management",
          "icon": "money-bag-outline",
          "title": "Budget and Resource Management - Optimize API Investments",
          "description": "Optimize budget and resource management for API initiatives to ensure effective investments and resource allocation.",
          "whyItMatters": "Effective budget and resource management is essential for ensuring that API initiatives are well-funded and resourced. This station provides guidelines for optimizing budget and resource management, ensuring that API initiatives are aligned with business goals and deliver maximum value.",
          "applyInWork": "Provide budget management frameworks, prioritization criteria, and monitoring tools for API initiatives. Ensure teams effectively manage budgets and resources, optimizing investments in API development and management to deliver maximum value.",
          "group": "Supporting Stations",
          "lifecycleStage": "supporting",
          "outcomes": [
            "Budget and resource management practices established for API initiatives",
            "Effective allocation of resources to API initiatives",
            "Optimized investments in API development and management",
            "Improved financial visibility and control over API initiatives"
          ],
          "steps": [
            {
              "text": "Define budget and resource management practices that outline the processes for managing budgets and resources for API initiatives.",
              "resourceId": "api-portfolio-management-guidelines",
              "resourceTitle": "API Portfolio Management Guidelines",
              "canvasId": null
            }
          ],
          "questions": [
            "Define budget and resource management practices that outline the processes for managing budgets and resources for API initiatives.",
            "Provide budget management frameworks, prioritization criteria, and monitoring tools for API initiatives. Ensure teams effectively manage budgets and resources, optimizing investments in API development and management to deliver maximum value.",
            "Effective budget and resource management is essential for ensuring that API initiatives are well-funded and resourced. This station provides guidelines for optimizing budget and resource management, ensuring that API initiatives are aligned with business goals and deliver maximum value."
          ],
          "criteria": [],
          "criteriaDetails": [],
          "stakeholders": [],
          "evidence": []
        }
      ],
      "stakeholders": [
        {
          "id": "api-architect",
          "sourceKey": "api-architect",
          "sourceStakeholderId": "api-architect",
          "title": "API Architect",
          "description": "Owns API architecture, design principles, and interface contract quality.",
          "involvement": ""
        },
        {
          "id": "api-consumer-specialist",
          "sourceKey": "api-consumer-specialist",
          "sourceStakeholderId": "api-consumer-specialist",
          "title": "API Consumer Representative",
          "description": "Represents the needs of developers, integrators, or other API consumers who use the API directly.",
          "involvement": ""
        },
        {
          "id": "api-designer",
          "sourceKey": "api-designer",
          "sourceStakeholderId": "api-designer",
          "title": "API Designer",
          "description": "Shapes the interface contract, interaction model, consistency, and usability of the exposed capabilities.",
          "involvement": ""
        },
        {
          "id": "governance-specialist",
          "sourceKey": "governance-specialist",
          "sourceStakeholderId": "governance-specialist",
          "title": "API Governance Owner",
          "description": "Represents review, audit, and organization-wide governance practices for API quality and conformity.",
          "involvement": ""
        },
        {
          "id": "api-product-owner",
          "sourceKey": "api-product-owner",
          "sourceStakeholderId": "api-product-owner",
          "title": "API Product Owner",
          "description": "Drives the API opportunity, prioritization, and product-level decisions across the lifecycle.",
          "involvement": ""
        },
        {
          "id": "api-program-owner",
          "sourceKey": "api-program-owner",
          "sourceStakeholderId": "api-program-owner",
          "title": "API Program Owner",
          "description": "Coordinates API portfolio practices, organizational alignment, and long-term API capability development.",
          "involvement": ""
        },
        {
          "id": "automation-engineer",
          "sourceKey": "automation-engineer",
          "sourceStakeholderId": "automation-engineer",
          "title": "Automation Engineer",
          "description": "Implements, tests, integrates, and maintains automation solutions and supporting workflows.",
          "involvement": ""
        },
        {
          "id": "automation-owner",
          "sourceKey": "automation-owner",
          "sourceStakeholderId": "automation-owner",
          "title": "Automation Owner",
          "description": "Owns automation goals, business value, priorities, controls, and lifecycle outcomes.",
          "involvement": ""
        },
        {
          "id": "business-owner",
          "sourceKey": "business-owner",
          "sourceStakeholderId": "business-owner",
          "title": "Business Owner",
          "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
          "involvement": ""
        },
        {
          "id": "capability-owner",
          "sourceKey": "capability-owner",
          "sourceStakeholderId": "capability-owner",
          "title": "Capability Owner",
          "description": "Owns the capability vision, value, priorities, lifecycle, and reuse across consumers.",
          "involvement": ""
        },
        {
          "id": "compliance-specialist",
          "sourceKey": "compliance-specialist",
          "sourceStakeholderId": "compliance-specialist",
          "title": "Compliance and Legal Specialist",
          "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
          "involvement": ""
        },
        {
          "id": "customer-specialist",
          "sourceKey": "customer-specialist",
          "sourceStakeholderId": "customer-specialist",
          "title": "Customer or Partner Representative",
          "description": "Contributes the business customer or partner perspective for the journey, value, and collaboration model.",
          "involvement": ""
        },
        {
          "id": "api-engineer",
          "sourceKey": "api-engineer",
          "sourceStakeholderId": "api-engineer",
          "title": "Delivery Engineer",
          "description": "Owns implementation, automation, testing, and release flow concerns needed to deliver the capability, API, or automation reliably.",
          "involvement": ""
        },
        {
          "id": "api-devrel-specialist",
          "sourceKey": "api-devrel-specialist",
          "sourceStakeholderId": "api-devrel-specialist",
          "title": "Documentation and DevRel Owner",
          "description": "Owns onboarding content, developer communication, and documentation quality for API consumers.",
          "involvement": ""
        },
        {
          "id": "domain-specialist",
          "sourceKey": "domain-specialist",
          "sourceStakeholderId": "domain-specialist",
          "title": "Domain Expert",
          "description": "Brings deep knowledge of the business domain, concepts, rules, and constraints the capability or interface must reflect.",
          "involvement": ""
        },
        {
          "id": "integration-architect",
          "sourceKey": "integration-architect",
          "sourceStakeholderId": "integration-architect",
          "title": "Integration Architect",
          "description": "Designs integration approaches and implementation styles that connect the capability or API with other systems.",
          "involvement": ""
        },
        {
          "id": "partner-specialist",
          "sourceKey": "partner-specialist",
          "sourceStakeholderId": "partner-specialist",
          "title": "Partner or Vendor Manager",
          "description": "Coordinates external partner, supplier, or vendor relationships that influence capability or API strategy and delivery.",
          "involvement": ""
        },
        {
          "id": "platform-architect",
          "sourceKey": "platform-architect",
          "sourceStakeholderId": "platform-architect",
          "title": "Platform Architect",
          "description": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
          "involvement": ""
        },
        {
          "id": "platform-owner",
          "sourceKey": "platform-owner",
          "sourceStakeholderId": "platform-owner",
          "title": "Platform Owner",
          "description": "Owns platform capabilities, roadmap, operational model, and service expectations.",
          "involvement": ""
        },
        {
          "id": "process-owner",
          "sourceKey": "process-owner",
          "sourceStakeholderId": "process-owner",
          "title": "Process Owner",
          "description": "Owns the business process being automated, including objectives, rules, outcomes, and improvement priorities.",
          "involvement": ""
        },
        {
          "id": "security-specialist",
          "sourceKey": "security-specialist",
          "sourceStakeholderId": "security-specialist",
          "title": "Security Specialist",
          "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
          "involvement": ""
        },
        {
          "id": "operations-specialist",
          "sourceKey": "operations-specialist",
          "sourceStakeholderId": "operations-specialist",
          "title": "Support and Operations Owner",
          "description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
          "involvement": ""
        }
      ],
      "routeProfiles": [
        {
          "id": "api-architect",
          "stakeholderId": "api-architect",
          "title": "API Architect",
          "summary": "Owns API architecture, design principles, and interface contract quality.",
          "stakeholder": {
            "id": "api-architect",
            "sourceKey": "api-architect",
            "sourceStakeholderId": "api-architect",
            "title": "API Architect",
            "description": "Owns API architecture, design principles, and interface contract quality.",
            "involvement": ""
          },
          "cycles": [
            {
              "id": "api-productization-cycle",
              "title": "API Productization Cycle",
              "description": "The API-focused APIOps Cycles journey for productizing, designing, delivering, publishing, and improving APIs."
            },
            {
              "id": "integration-productization-cycle",
              "title": "Integration Productization Cycle",
              "description": "A cycle for productizing reusable integration capabilities before selecting the implementation style."
            }
          ],
          "stations": [
            {
              "id": "api-platform-architecture",
              "title": "Architecture & Platform Decisions",
              "description": "Use requirements and constraints to decide the right architecture pattern and enabling platform capabilities."
            }
          ],
          "canvases": [
            {
              "id": "businessImpactCanvas",
              "title": "Business Impact Canvas"
            },
            {
              "id": "locationsCanvas",
              "title": "Locations Canvas"
            },
            {
              "id": "capacityCanvas",
              "title": "Capacity Canvas"
            }
          ],
          "decisions": [
            "Use the Business Impact Canvas to identify availability, security, and data risks that influence architecture options.",
            "Use the Locations Canvas to capture geopolitical, regulatory, network, residency, and trust-boundary constraints.",
            "Use the Capacity Canvas to capture current and future volumes, peaks, latency, caching, rate limiting, and scaling expectations.",
            "Use metrics and analytics guidance to define how the chosen capability will be monitored and improved.",
            "Compare viable architecture styles against the gathered requirements and document the selected pattern and rationale.",
            "Architecture choices should follow from evidence about business impact, locations, trust boundaries, capacity, latency, data ownership, consistency, operability, security, privacy, governance, and cost."
          ],
          "outputs": [
            "A justified architecture choice",
            "Documented risks, locations, capacity, security, privacy, and operability constraints",
            "Clear rationale for API, event, file, stream, data product, direct integration, or hybrid implementation style",
            "architecture-decision",
            "documentation",
            "platform-config",
            "metrics"
          ],
          "recommendedResources": [
            {
              "id": "businessImpactCanvas",
              "slug": "resources/business-impact-canvas",
              "title": "Business Impact Canvas",
              "description": "Identify business, availability, security, data, compliance, and operational risks that should shape architecture and platform decisions.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 4,
              "outcomes": [
                "Documented business and operational impact assessment",
                "Prioritized risks and mitigation actions",
                "Evidence for architecture and platform decisions"
              ],
              "steps": [
                "Availability Risks: Identify risks and impacts.",
                "Ways to Mitigate Availability Risks: Define mitigation measures.",
                "Security Risks: Document security-related risks.",
                "Ways to Mitigate Security Risks: Propose strategies to mitigate security risks.",
                "Data Risks: Identify risks to data accuracy or availability.",
                "Ways to Mitigate Data Risks: Plan strategies to address data risks."
              ],
              "canvasId": "businessImpactCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "locationsCanvas",
              "slug": "resources/location-canvas",
              "title": "Location Canvas",
              "description": "Map consumer, producer, system, data, network, regulatory, and trust-boundary locations to ensure compliance and performance across regions.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 6,
              "outcomes": [
                "Documented location, residency, network, and regulatory requirements",
                "Regional performance and accessibility constraints identified",
                "Data residency, trust boundaries, and applicable regulations clarified"
              ],
              "steps": [
                "Map locations of producers, source systems, platforms, and consumers.",
                "Document where consumers are located.",
                "Identify applicable regulations.",
                "Document where data must reside.",
                "Ensure the capability is accessible in all intended network regions.",
                "Validate network performance across regions."
              ],
              "canvasId": "locationsCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capacityCanvas",
              "slug": "resources/capacity-canvas",
              "title": "Capacity Canvas",
              "description": "Plan capacity for current and future demand, including volumes, peaks, latency, availability, scaling, caching, and rate limits for the selected capability and implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 7,
              "outcomes": [
                "Capacity requirements aligned with expected business demand",
                "Peak-load, availability, and growth assumptions documented",
                "Scaling, caching, and rate-limiting decisions defined"
              ],
              "steps": [
                "Document current business volumes",
                "Forecast future consumption trends",
                "Plan for peak load and availability requirements",
                "Define caching and rate-limiting strategies",
                "Propose scaling strategies"
              ],
              "canvasId": "capacityCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "api-metrics-and-analytics",
              "slug": "resources/api-metrics-and-analytics",
              "title": "API Metrics And Analytics",
              "description": "A resource for defining, collecting, and analyzing API performance and usage data to align technical KPIs with business outcomes.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 119,
              "outcomes": [
                "Shared understanding of the purpose and use of API Metrics And Analytics",
                "A consistent approach to applying API Metrics And Analytics",
                "Improved application of the related practices"
              ],
              "steps": [
                "Identify key performance indicators (KPIs) to measure API success against business goals.",
                "Define and monitor performance metrics (e.g., API calls, latency, error rates) and adoption metrics (e.g., NPS).",
                "Monitor API initiatives to ensure adherence to operating guidelines and governance practices"
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "partner-integration-guidelines",
              "slug": "resources/partner-integration-guidelines",
              "title": "Partner Integration Guidelines",
              "description": "Integration checklists and communication patterns to manage technical and legal aspects of third-party API relationships.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 164,
              "outcomes": [
                "Shared understanding of the purpose and use of Partner Integration Guidelines",
                "A consistent approach to applying Partner Integration Guidelines",
                "Improved application of the related practices"
              ],
              "steps": [
                "Establish integration processes and guidelines for collaborating with partners, including technical integration, data sharing, and support.",
                "Monitor partner API performance and compliance to ensure reliability and alignment with your API strategy."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            }
          ],
          "promptIds": [
            "api-architect:facilitate-station",
            "api-architect:use-resources",
            "api-architect:next-actions"
          ]
        },
        {
          "id": "api-consumer-specialist",
          "stakeholderId": "api-consumer-specialist",
          "title": "API Consumer Representative",
          "summary": "Represents the needs of developers, integrators, or other API consumers who use the API directly.",
          "stakeholder": {
            "id": "api-consumer-specialist",
            "sourceKey": "api-consumer-specialist",
            "sourceStakeholderId": "api-consumer-specialist",
            "title": "API Consumer Representative",
            "description": "Represents the needs of developers, integrators, or other API consumers who use the API directly.",
            "involvement": ""
          },
          "cycles": [
            {
              "id": "capability-productization-cycle",
              "title": "Capability Productization Cycle",
              "description": "A cycle for turning business capabilities into reusable digital capabilities before selecting the implementation style."
            },
            {
              "id": "api-productization-cycle",
              "title": "API Productization Cycle",
              "description": "The API-focused APIOps Cycles journey for productizing, designing, delivering, publishing, and improving APIs."
            },
            {
              "id": "integration-productization-cycle",
              "title": "Integration Productization Cycle",
              "description": "A cycle for productizing reusable integration capabilities before selecting the implementation style."
            },
            {
              "id": "automation-cycle",
              "title": "Automation Cycle",
              "description": "A cycle for identifying, designing, delivering, enabling, and improving automation opportunities."
            }
          ],
          "stations": [
            {
              "id": "api-consumer-experience",
              "title": "Consumer Requirements & Onboarding",
              "description": "Capture consumer onboarding, standards, non-functional requirements, service expectations, constraints, security needs, allowed protocols, data freshness, SLAs, observability, recovery, adoption requirements, and producer responsibilities."
            },
            {
              "id": "api-design",
              "title": "Solution & Interface Design",
              "description": "Design the interface contract and interaction model after the architecture choice is justified."
            },
            {
              "id": "api-publishing",
              "title": "Publishing & Enablement",
              "description": "Publish reusable capability information so consumers can discover, request, onboard, use, and get support."
            },
            {
              "id": "monitoring-and-improving",
              "title": "Monitoring & Improvement",
              "description": "Monitor usage, reliability, data quality, consumer outcomes, operational cost, and reuse opportunities after release."
            },
            {
              "id": "api-product-strategy",
              "title": "Strategy",
              "description": "Frame the business need as a reusable capability before choosing the implementation style."
            },
            {
              "id": "api-platform-architecture",
              "title": "Architecture & Platform Decisions",
              "description": "Use requirements and constraints to decide the right architecture pattern and enabling platform capabilities."
            }
          ],
          "canvases": [
            {
              "id": "consumerExperienceRequirementsCanvas",
              "title": "Consumer Experience Requirements Canvas"
            },
            {
              "id": "domainCanvas",
              "title": "Domain Canvas"
            },
            {
              "id": "interactionCanvas",
              "title": "Interaction Canvas"
            },
            {
              "id": "customerJourneyCanvas",
              "title": "Customer Journey Canvas"
            },
            {
              "id": "capabilityValuePropositionCanvas",
              "title": "Capability Value Proposition Canvas"
            },
            {
              "id": "capabilityBusinessModelCanvas",
              "title": "Capability Business Model Canvas"
            },
            {
              "id": "businessImpactCanvas",
              "title": "Business Impact Canvas"
            },
            {
              "id": "locationsCanvas",
              "title": "Locations Canvas"
            },
            {
              "id": "capacityCanvas",
              "title": "Capacity Canvas"
            },
            {
              "id": "apiValuePropositionCanvas",
              "title": "API Value Proposition Canvas"
            },
            {
              "id": "restCanvas",
              "title": "REST Canvas"
            },
            {
              "id": "eventCanvas",
              "title": "Event Canvas"
            },
            {
              "id": "graphqlCanvas",
              "title": "GraphQL Canvas"
            },
            {
              "id": "apiBusinessModelCanvas",
              "title": "API Business Model Canvas"
            }
          ],
          "decisions": [
            "Use the Consumer Experience Requirements Canvas to capture consumer goals, availability, freshness, volume, performance, data quality, security, onboarding, change, observability, and recovery expectations.",
            "Use onboarding guidance to describe how consumers will find, request, test, get approved for, and start using the capability.",
            "Use the resulting journey and requirements to improve onboarding, documentation, support, and feedback loops for capability consumers.",
            "Use consumer experience and onboarding guidance to make expectations explicit for both consumers and producers.",
            "The right architecture depends on consumer goals, onboarding expectations, service levels, data quality needs, change tolerance, observability, support, and producer constraints.",
            "Reuse the Domain Canvas to confirm business objects, terms, rules, and ownership before contract design."
          ],
          "outputs": [
            "Documented consumer requirements and onboarding expectations",
            "Clear producer responsibilities and support expectations",
            "Architecture-relevant constraints ready for decision making",
            "Improved adoption through consumer empathy, standards, and producer clarity",
            "design-artifact",
            "documentation",
            "consumer-feedback",
            "A validated interface contract for the selected implementation style"
          ],
          "recommendedResources": [
            {
              "id": "consumerExperienceRequirementsCanvas",
              "slug": "resources/consumer-experience-requirements-canvas",
              "title": "Consumer Experience Requirements Canvas",
              "description": "A requirements canvas for consumer experience and non-functional needs that should guide the later architecture and implementation-style decision.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 3.2,
              "outcomes": [
                "Technology-agnostic consumer and service requirements",
                "Experience and non-functional needs captured before design starts",
                "Architecture implications documented for implementation-style selection"
              ],
              "steps": [
                "Capture consumer goals and usage context.",
                "Document availability, timeliness, volume, performance, data quality, and consistency expectations.",
                "Document security, privacy, onboarding, change, observability, support, and recovery expectations.",
                "Summarize what the requirements imply for possible implementation styles."
              ],
              "canvasId": "consumerExperienceRequirementsCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "api-onboarding-best-practices",
              "slug": "resources/api-onboarding-best-practices",
              "title": "API Onboarding Best Practices",
              "description": "Best practices to streamline API consumer onboarding journeys with step-by-step registration, discovery, and first-call guidance.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 121,
              "outcomes": [
                "Shared understanding of the purpose and use of API Onboarding Best Practices",
                "A consistent approach to applying API Onboarding Best Practices",
                "Improved application of the related practices"
              ],
              "steps": [
                "Define the API consumer journey from discovery to troubleshooting, identifying key touchpoints and pain points.",
                "Develop onboarding processes and resources to help API consumers understand how to use APIs effectively.",
                "Document how consumers find and use the API, including onboarding processes and registration."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "domainCanvas",
              "slug": "resources/domain-canvas",
              "title": "Domain Canvas",
              "description": "A modeling tool to define and communicate the key entities and relationships in your domain, ensuring semantic consistency across capabilities, integrations, APIs, data products, and services.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 152,
              "outcomes": [
                "Shared domain model and terminology",
                "Core entities, relationships, rules, and ownership clarified",
                "Semantic consistency across capabilities, integrations, APIs, data products, and services"
              ],
              "steps": [
                "Define core entities, their attributes, and relationships to create a shared conceptual understanding across capabilities, integrations, APIs, data products, and services."
              ],
              "canvasId": "domainCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "interactionCanvas",
              "slug": "resources/interaction-canvas",
              "title": "Interaction Canvas",
              "description": "Define interactions, workflows, inputs, outputs, commands, queries, events, and expected responses to ensure a consistent consumer experience.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 9,
              "outcomes": [
                "Defined interaction model for the selected capability",
                "Inputs, outputs, commands, queries, events, and responses clarified",
                "Validation rules and interaction expectations agreed"
              ],
              "steps": [
                "Map interactions to user, consumer, or system tasks",
                "Define access points, operations, commands, queries, or events for each interaction",
                "Document inputs and outputs for each interaction.",
                "Specify validation rules and constraints",
                "Create interaction models for CRUD, query-driven, command-driven, and event-driven interactions"
              ],
              "canvasId": "interactionCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "contract-first-design",
              "slug": "resources/contract-first-design",
              "title": "Contract First Design",
              "description": "A guideline advocating for API-first approaches using formal contracts (e.g., OpenAPI) to align stakeholders before development.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 146,
              "outcomes": [
                "Shared understanding of the purpose and use of Contract First Design",
                "A consistent approach to applying Contract First Design",
                "Improved application of the related practices"
              ],
              "steps": [
                "Apply contract-first or design-first approaches to ensure API interface contracts are validated before implementation.",
                "Define API interface contracts that outline the expectations, responsibilities, and usage guidelines for each API.",
                "Use standardized formats (e.g., OpenAPI, AsyncAPI) to create machine-readable API interface contracts that are easy to share and validate."
              ],
              "canvasId": null,
              "sourcePath": "src/snippets/api-contract-example.yaml",
              "sourceUrl": null,
              "contentMarkdown": "openapi: 3.0.3\r\ninfo:\r\n  title: Sample Catalog API\r\n  version: 1.0.0\r\n  description: |\r\n    Starter example for a read-only APIOps Cycles API.\r\n    This example keeps the contract audit-friendly and easy to extend.\r\nservers:\r\n  - url: /v1\r\n    description: Versioned API base path\r\ntags:\r\n  - name: catalog\r\n    description: Browse and search catalog items\r\npaths:\r\n  /items:\r\n    get:\r\n      tags: [catalog]\r\n      summary: List catalog items\r\n      description: Returns a paginated list of public catalog items.\r\n      operationId: listItems\r\n      parameters:\r\n        - $ref: \"#/components/parameters/searchTerm\"\r\n        - $ref: \"#/components/parameters/categoryId\"\r\n        - $ref: \"#/components/parameters/page\"\r\n        - $ref: \"#/components/parameters/pageSize\"\r\n      responses:\r\n        \"200\":\r\n          description: Item list\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemListResponse\"\r\n              examples:\r\n                default:\r\n                  value:\r\n                    data:\r\n                      - itemId: item-123\r\n                        slug: blue-widget\r\n                        name: Blue Widget\r\n                        status: published\r\n                    page:\r\n                      number: 1\r\n                      size: 20\r\n                      totalItems: 1\r\n        \"400\":\r\n          $ref: \"#/components/responses/BadRequest\"\r\n        \"429\":\r\n          $ref: \"#/components/responses/TooManyRequests\"\r\n  /items/{itemId}:\r\n    get:\r\n      tags: [catalog]\r\n      summary: Get item by id\r\n      description: Returns a single public catalog item by opaque identifier.\r\n      operationId: getItemById\r\n      parameters:\r\n        - $ref: \"#/components/parameters/itemId\"\r\n      responses:\r\n        \"200\":\r\n          description: Item details\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemDetail\"\r\n        \"400\":\r\n          $ref: \"#/components/responses/BadRequest\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\n  /items/by-slug/{slug}:\r\n    get:\r\n      tags: [catalog]\r\n      summary: Get item by slug\r\n      description: Returns a single item by public slug.\r\n      operationId: getItemBySlug\r\n      parameters:\r\n        - $ref: \"#/components/parameters/slug\"\r\n      responses:\r\n        \"200\":\r\n          description: Item details\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemDetail\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\n  /categories/{categoryId}/items:\r\n    get:\r\n      tags: [catalog]\r\n      summary: List items in category\r\n      description: Returns public items in a category.\r\n      operationId: listItemsByCategory\r\n      parameters:\r\n        - $ref: \"#/components/parameters/categoryId\"\r\n      responses:\r\n        \"200\":\r\n          description: Category item list\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemListResponse\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\ncomponents:\r\n  parameters:\r\n    itemId:\r\n      name: itemId\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9][a-z0-9-]{1,63}$\"\r\n      example: item-123\r\n    slug:\r\n      name: slug\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9]+(?:-[a-z0-9]+)*$\"\r\n      example: blue-widget\r\n    categoryId:\r\n      name: categoryId\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9][a-z0-9-]{1,63}$\"\r\n      example: home-goods\r\n    searchTerm:\r\n      name: searchTerm\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: string\r\n        minLength: 1\r\n      example: widget\r\n    page:\r\n      name: page\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: integer\r\n        minimum: 1\r\n        default: 1\r\n    pageSize:\r\n      name: pageSize\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: integer\r\n        minimum: 1\r\n        maximum: 100\r\n        default: 20\r\n  responses:\r\n    BadRequest:\r\n      description: Validation failed\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n          examples:\r\n            default:\r\n              value:\r\n                code: BAD_REQUEST\r\n                message: Invalid request\r\n    NotFound:\r\n      description: Resource not found\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n    TooManyRequests:\r\n      description: Rate limit exceeded\r\n      headers:\r\n        Retry-After:\r\n          schema:\r\n            type: integer\r\n          description: Seconds until the next allowed request.\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n  schemas:\r\n    ItemListResponse:\r\n      type: object\r\n      required: [data, page]\r\n      properties:\r\n        data:\r\n          type: array\r\n          items:\r\n            $ref: \"#/components/schemas/ItemSummary\"\r\n        page:\r\n          $ref: \"#/components/schemas/Page\"\r\n    ItemSummary:\r\n      type: object\r\n      required: [itemId, slug, name, status]\r\n      properties:\r\n        itemId:\r\n          type: string\r\n        slug:\r\n          type: string\r\n        name:\r\n          type: string\r\n        status:\r\n          type: string\r\n          enum: [published, hidden]\r\n    ItemDetail:\r\n      allOf:\r\n        - $ref: \"#/components/schemas/ItemSummary\"\r\n        - type: object\r\n          properties:\r\n            description:\r\n              type: string\r\n            categories:\r\n              type: array\r\n              items:\r\n                type: string\r\n            variants:\r\n              type: array\r\n              items:\r\n                $ref: \"#/components/schemas/Variant\"\r\n    Variant:\r\n      type: object\r\n      required: [variantId, sku, price, inventory]\r\n      properties:\r\n        variantId:\r\n          type: string\r\n        sku:\r\n          type: string\r\n        price:\r\n          $ref: \"#/components/schemas/Price\"\r\n        inventory:\r\n          $ref: \"#/components/schemas/Inventory\"\r\n    Price:\r\n      type: object\r\n      required: [amount, currency]\r\n      properties:\r\n        amount:\r\n          type: number\r\n          format: decimal\r\n        currency:\r\n          type: string\r\n          example: EUR\r\n    Inventory:\r\n      type: object\r\n      required: [available]\r\n      properties:\r\n        available:\r\n          type: integer\r\n          minimum: 0\r\n        reserved:\r\n          type: integer\r\n          minimum: 0\r\n        source:\r\n          type: string\r\n    Page:\r\n      type: object\r\n      required: [number, size, totalItems]\r\n      properties:\r\n        number:\r\n          type: integer\r\n        size:\r\n          type: integer\r\n        totalItems:\r\n          type: integer\r\n    ErrorResponse:\r\n      type: object\r\n      required: [code, message]\r\n      properties:\r\n        code:\r\n          type: string\r\n        message:\r\n          type: string\r\n",
              "draft": true
            },
            {
              "id": "service-agreement-template",
              "slug": "resources/service-agreement-template",
              "title": "Service Agreement Template",
              "description": "A customizable agreement format that defines expectations, SLAs, responsibilities, and access terms for API consumption.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 172,
              "outcomes": [
                "Shared understanding of the purpose and use of Service Agreement Template",
                "A consistent approach to applying Service Agreement Template",
                "Improved application of the related practices"
              ],
              "steps": [
                "Define service agreements that outline the expectations, service levels, and responsibilities for each API.",
                "Use standardized formats to create machine-readable service agreements that are easy to share and validate.",
                "Ensure service agreements are reviewed and approved by stakeholders to ensure alignment and clarity."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "api-metrics-and-analytics",
              "slug": "resources/api-metrics-and-analytics",
              "title": "API Metrics And Analytics",
              "description": "A resource for defining, collecting, and analyzing API performance and usage data to align technical KPIs with business outcomes.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 119,
              "outcomes": [
                "Shared understanding of the purpose and use of API Metrics And Analytics",
                "A consistent approach to applying API Metrics And Analytics",
                "Improved application of the related practices"
              ],
              "steps": [
                "Identify key performance indicators (KPIs) to measure API success against business goals.",
                "Define and monitor performance metrics (e.g., API calls, latency, error rates) and adoption metrics (e.g., NPS).",
                "Monitor API initiatives to ensure adherence to operating guidelines and governance practices"
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "api-community-engagement-strategies",
              "slug": "resources/api-community-engagement-strategies",
              "title": "API Community Engagement Strategies",
              "description": "A playbook for fostering API adoption by cultivating communities through content, support channels, feedback loops, and social engagement strategies.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 103,
              "outcomes": [
                "Shared understanding of the purpose and use of API Community Engagement Strategies",
                "A consistent approach to applying API Community Engagement Strategies",
                "Improved application of the related practices"
              ],
              "steps": [
                "Develop marketing strategies to promote APIs to target audiences, including social media, blogs, and webinars.",
                "Create promotional materials (e.g., case studies, success stories) that highlight the value and benefits of APIs.",
                "Create educational materials (e.g., tutorials, documentation) that explain API features, benefits, and usage patterns.",
                "Engage with API consumers through feedback loops, support channels, and community forums to understand their needs and improve API adoption.",
                "Analyze API usage metrics and incorporate user feedback into API iterations."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "customerJourneyCanvas",
              "slug": "resources/customer-journey-canvas",
              "title": "Customer Journey Canvas",
              "description": "Map customer, partner, or consumer journeys to identify needs, pain points, gains, inputs, outputs, and experience expectations.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 1,
              "outcomes": [
                "Shared understanding of the customer, partner, or consumer journey",
                "Needs, pain points, gains, inputs, and outputs documented",
                "Journey evidence available for capability, requirements, and architecture decisions"
              ],
              "steps": [
                "Define customer persona",
                "Identify triggers for the journey",
                "Describe the journey's end",
                "Map journey steps with inputs/outputs",
                "Identify customer pains",
                "Summarize customer gains",
                "Define necessary inputs and resulting outputs",
                "Define interactions and processing expectations for each step"
              ],
              "canvasId": "customerJourneyCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capabilityValuePropositionCanvas",
              "slug": "resources/capability-value-proposition-canvas",
              "title": "Capability Value Proposition Canvas",
              "description": "A technology-agnostic canvas for mapping consumer tasks, gains, pains, and candidate reusable capabilities before selecting an implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 2.1,
              "outcomes": [
                "Clear reusable capability value proposition",
                "Consumer tasks, gains, and pains captured without assuming a technology",
                "Candidate reusable capabilities identified for architecture evaluation"
              ],
              "steps": [
                "List the consumer tasks and outcomes the capability should support.",
                "Identify gain-enabling capability features.",
                "Identify pain-relieving capability features.",
                "Group the features into candidate reusable capabilities."
              ],
              "canvasId": "capabilityValuePropositionCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            }
          ],
          "promptIds": [
            "api-consumer-specialist:facilitate-station",
            "api-consumer-specialist:use-resources",
            "api-consumer-specialist:next-actions"
          ]
        },
        {
          "id": "api-designer",
          "stakeholderId": "api-designer",
          "title": "API Designer",
          "summary": "Shapes the interface contract, interaction model, consistency, and usability of the exposed capabilities.",
          "stakeholder": {
            "id": "api-designer",
            "sourceKey": "api-designer",
            "sourceStakeholderId": "api-designer",
            "title": "API Designer",
            "description": "Shapes the interface contract, interaction model, consistency, and usability of the exposed capabilities.",
            "involvement": ""
          },
          "cycles": [
            {
              "id": "capability-productization-cycle",
              "title": "Capability Productization Cycle",
              "description": "A cycle for turning business capabilities into reusable digital capabilities before selecting the implementation style."
            },
            {
              "id": "api-productization-cycle",
              "title": "API Productization Cycle",
              "description": "The API-focused APIOps Cycles journey for productizing, designing, delivering, publishing, and improving APIs."
            },
            {
              "id": "integration-productization-cycle",
              "title": "Integration Productization Cycle",
              "description": "A cycle for productizing reusable integration capabilities before selecting the implementation style."
            },
            {
              "id": "automation-cycle",
              "title": "Automation Cycle",
              "description": "A cycle for identifying, designing, delivering, enabling, and improving automation opportunities."
            }
          ],
          "stations": [
            {
              "id": "api-design",
              "title": "Solution & Interface Design",
              "description": "Design the interface contract and interaction model after the architecture choice is justified."
            },
            {
              "id": "api-delivery",
              "title": "Delivery & Operations",
              "description": "Deliver the selected implementation style with appropriate engineering, testing, security, automation, and operational practices."
            },
            {
              "id": "api-audit",
              "title": "Quality & Readiness Assurance",
              "description": "Audit the capability interface contract, controls, support model, observability, documentation, and lifecycle readiness before release."
            },
            {
              "id": "api-consumer-experience",
              "title": "Consumer Requirements & Onboarding",
              "description": "Capture consumer onboarding, standards, non-functional requirements, service expectations, constraints, security needs, allowed protocols, data freshness, SLAs, observability, recovery, adoption requirements, and producer responsibilities."
            }
          ],
          "canvases": [
            {
              "id": "domainCanvas",
              "title": "Domain Canvas"
            },
            {
              "id": "interactionCanvas",
              "title": "Interaction Canvas"
            },
            {
              "id": "consumerExperienceRequirementsCanvas",
              "title": "Consumer Experience Requirements Canvas"
            },
            {
              "id": "restCanvas",
              "title": "REST Canvas"
            },
            {
              "id": "eventCanvas",
              "title": "Event Canvas"
            },
            {
              "id": "graphqlCanvas",
              "title": "GraphQL Canvas"
            },
            {
              "id": "apiValuePropositionCanvas",
              "title": "API Value Proposition Canvas"
            },
            {
              "id": "customerJourneyCanvas",
              "title": "Customer Journey Canvas"
            }
          ],
          "decisions": [
            "Reuse the Domain Canvas to confirm business objects, terms, rules, and ownership before contract design.",
            "Use the Interaction Canvas to describe how consumers, systems, or users interact with the capability.",
            "Use REST design resources when the selected interface is a REST API.",
            "Use Event Canvas resources when the selected interface is event-driven.",
            "Use GraphQL design resources when the selected interface is GraphQL.",
            "Use the design principles and style guidance to align design decisions with shared rules and enable consistent audit validation."
          ],
          "outputs": [
            "A validated interface contract for the selected implementation style",
            "Consistent interaction, data, event, file, workflow, or API contract decisions",
            "Design traceability back to capability and consumer requirements",
            "Designs aligned with domain models and interaction patterns",
            "spec",
            "contract",
            "design-artifact",
            "documentation"
          ],
          "recommendedResources": [
            {
              "id": "domainCanvas",
              "slug": "resources/domain-canvas",
              "title": "Domain Canvas",
              "description": "A modeling tool to define and communicate the key entities and relationships in your domain, ensuring semantic consistency across capabilities, integrations, APIs, data products, and services.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 152,
              "outcomes": [
                "Shared domain model and terminology",
                "Core entities, relationships, rules, and ownership clarified",
                "Semantic consistency across capabilities, integrations, APIs, data products, and services"
              ],
              "steps": [
                "Define core entities, their attributes, and relationships to create a shared conceptual understanding across capabilities, integrations, APIs, data products, and services."
              ],
              "canvasId": "domainCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "interactionCanvas",
              "slug": "resources/interaction-canvas",
              "title": "Interaction Canvas",
              "description": "Define interactions, workflows, inputs, outputs, commands, queries, events, and expected responses to ensure a consistent consumer experience.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 9,
              "outcomes": [
                "Defined interaction model for the selected capability",
                "Inputs, outputs, commands, queries, events, and responses clarified",
                "Validation rules and interaction expectations agreed"
              ],
              "steps": [
                "Map interactions to user, consumer, or system tasks",
                "Define access points, operations, commands, queries, or events for each interaction",
                "Document inputs and outputs for each interaction.",
                "Specify validation rules and constraints",
                "Create interaction models for CRUD, query-driven, command-driven, and event-driven interactions"
              ],
              "canvasId": "interactionCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "contract-first-design",
              "slug": "resources/contract-first-design",
              "title": "Contract First Design",
              "description": "A guideline advocating for API-first approaches using formal contracts (e.g., OpenAPI) to align stakeholders before development.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 146,
              "outcomes": [
                "Shared understanding of the purpose and use of Contract First Design",
                "A consistent approach to applying Contract First Design",
                "Improved application of the related practices"
              ],
              "steps": [
                "Apply contract-first or design-first approaches to ensure API interface contracts are validated before implementation.",
                "Define API interface contracts that outline the expectations, responsibilities, and usage guidelines for each API.",
                "Use standardized formats (e.g., OpenAPI, AsyncAPI) to create machine-readable API interface contracts that are easy to share and validate."
              ],
              "canvasId": null,
              "sourcePath": "src/snippets/api-contract-example.yaml",
              "sourceUrl": null,
              "contentMarkdown": "openapi: 3.0.3\r\ninfo:\r\n  title: Sample Catalog API\r\n  version: 1.0.0\r\n  description: |\r\n    Starter example for a read-only APIOps Cycles API.\r\n    This example keeps the contract audit-friendly and easy to extend.\r\nservers:\r\n  - url: /v1\r\n    description: Versioned API base path\r\ntags:\r\n  - name: catalog\r\n    description: Browse and search catalog items\r\npaths:\r\n  /items:\r\n    get:\r\n      tags: [catalog]\r\n      summary: List catalog items\r\n      description: Returns a paginated list of public catalog items.\r\n      operationId: listItems\r\n      parameters:\r\n        - $ref: \"#/components/parameters/searchTerm\"\r\n        - $ref: \"#/components/parameters/categoryId\"\r\n        - $ref: \"#/components/parameters/page\"\r\n        - $ref: \"#/components/parameters/pageSize\"\r\n      responses:\r\n        \"200\":\r\n          description: Item list\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemListResponse\"\r\n              examples:\r\n                default:\r\n                  value:\r\n                    data:\r\n                      - itemId: item-123\r\n                        slug: blue-widget\r\n                        name: Blue Widget\r\n                        status: published\r\n                    page:\r\n                      number: 1\r\n                      size: 20\r\n                      totalItems: 1\r\n        \"400\":\r\n          $ref: \"#/components/responses/BadRequest\"\r\n        \"429\":\r\n          $ref: \"#/components/responses/TooManyRequests\"\r\n  /items/{itemId}:\r\n    get:\r\n      tags: [catalog]\r\n      summary: Get item by id\r\n      description: Returns a single public catalog item by opaque identifier.\r\n      operationId: getItemById\r\n      parameters:\r\n        - $ref: \"#/components/parameters/itemId\"\r\n      responses:\r\n        \"200\":\r\n          description: Item details\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemDetail\"\r\n        \"400\":\r\n          $ref: \"#/components/responses/BadRequest\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\n  /items/by-slug/{slug}:\r\n    get:\r\n      tags: [catalog]\r\n      summary: Get item by slug\r\n      description: Returns a single item by public slug.\r\n      operationId: getItemBySlug\r\n      parameters:\r\n        - $ref: \"#/components/parameters/slug\"\r\n      responses:\r\n        \"200\":\r\n          description: Item details\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemDetail\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\n  /categories/{categoryId}/items:\r\n    get:\r\n      tags: [catalog]\r\n      summary: List items in category\r\n      description: Returns public items in a category.\r\n      operationId: listItemsByCategory\r\n      parameters:\r\n        - $ref: \"#/components/parameters/categoryId\"\r\n      responses:\r\n        \"200\":\r\n          description: Category item list\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemListResponse\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\ncomponents:\r\n  parameters:\r\n    itemId:\r\n      name: itemId\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9][a-z0-9-]{1,63}$\"\r\n      example: item-123\r\n    slug:\r\n      name: slug\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9]+(?:-[a-z0-9]+)*$\"\r\n      example: blue-widget\r\n    categoryId:\r\n      name: categoryId\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9][a-z0-9-]{1,63}$\"\r\n      example: home-goods\r\n    searchTerm:\r\n      name: searchTerm\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: string\r\n        minLength: 1\r\n      example: widget\r\n    page:\r\n      name: page\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: integer\r\n        minimum: 1\r\n        default: 1\r\n    pageSize:\r\n      name: pageSize\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: integer\r\n        minimum: 1\r\n        maximum: 100\r\n        default: 20\r\n  responses:\r\n    BadRequest:\r\n      description: Validation failed\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n          examples:\r\n            default:\r\n              value:\r\n                code: BAD_REQUEST\r\n                message: Invalid request\r\n    NotFound:\r\n      description: Resource not found\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n    TooManyRequests:\r\n      description: Rate limit exceeded\r\n      headers:\r\n        Retry-After:\r\n          schema:\r\n            type: integer\r\n          description: Seconds until the next allowed request.\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n  schemas:\r\n    ItemListResponse:\r\n      type: object\r\n      required: [data, page]\r\n      properties:\r\n        data:\r\n          type: array\r\n          items:\r\n            $ref: \"#/components/schemas/ItemSummary\"\r\n        page:\r\n          $ref: \"#/components/schemas/Page\"\r\n    ItemSummary:\r\n      type: object\r\n      required: [itemId, slug, name, status]\r\n      properties:\r\n        itemId:\r\n          type: string\r\n        slug:\r\n          type: string\r\n        name:\r\n          type: string\r\n        status:\r\n          type: string\r\n          enum: [published, hidden]\r\n    ItemDetail:\r\n      allOf:\r\n        - $ref: \"#/components/schemas/ItemSummary\"\r\n        - type: object\r\n          properties:\r\n            description:\r\n              type: string\r\n            categories:\r\n              type: array\r\n              items:\r\n                type: string\r\n            variants:\r\n              type: array\r\n              items:\r\n                $ref: \"#/components/schemas/Variant\"\r\n    Variant:\r\n      type: object\r\n      required: [variantId, sku, price, inventory]\r\n      properties:\r\n        variantId:\r\n          type: string\r\n        sku:\r\n          type: string\r\n        price:\r\n          $ref: \"#/components/schemas/Price\"\r\n        inventory:\r\n          $ref: \"#/components/schemas/Inventory\"\r\n    Price:\r\n      type: object\r\n      required: [amount, currency]\r\n      properties:\r\n        amount:\r\n          type: number\r\n          format: decimal\r\n        currency:\r\n          type: string\r\n          example: EUR\r\n    Inventory:\r\n      type: object\r\n      required: [available]\r\n      properties:\r\n        available:\r\n          type: integer\r\n          minimum: 0\r\n        reserved:\r\n          type: integer\r\n          minimum: 0\r\n        source:\r\n          type: string\r\n    Page:\r\n      type: object\r\n      required: [number, size, totalItems]\r\n      properties:\r\n        number:\r\n          type: integer\r\n        size:\r\n          type: integer\r\n        totalItems:\r\n          type: integer\r\n    ErrorResponse:\r\n      type: object\r\n      required: [code, message]\r\n      properties:\r\n        code:\r\n          type: string\r\n        message:\r\n          type: string\r\n",
              "draft": true
            },
            {
              "id": "api-development-best-practices",
              "slug": "resources/api-development-best-practices",
              "title": "API Development Best Practices",
              "description": "Implementation guidance for turning a validated API interface contract into a consistent, maintainable API codebase using standard libraries, reusable patterns, and aligned development workflows.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 112,
              "outcomes": [
                "Shared understanding of the purpose and use of API Development Best Practices",
                "A consistent approach to applying API Development Best Practices",
                "Improved application of the related practices"
              ],
              "steps": [
                "Apply these practices to the validated API interface contract and implementation plan before coding begins.",
                "Use established frameworks, libraries, and coding standards to implement the contract consistently and maintainably."
              ],
              "canvasId": null,
              "sourcePath": "src/snippets/api-design-principles-guidance.md",
              "sourceUrl": null,
              "contentMarkdown": "## How to start the API Delivery work based on the previous phases (\"stations\")\r\n\r\nUse this guidance at the start of `API Delivery` after the API contract (e.g. OpenAPI) and the key outputs from earlier stations have been reviewed and accepted.\r\n\r\nThe goal is not to invent implementation in isolation. The goal is to turn the agreed outputs from earlier stations into concrete code structure, validation rules, runtime behavior, and API product delivery decisions.\r\n\r\n---\r\n\r\n### 1. Start From The Validated Contract\r\n\r\n- Treat the validated API contract as the main reference point for implementation decisions.\r\n- Keep the contract and implementation aligned throughout the API product delivery.\r\n- Use the contract to drive request validation, response mapping, documentation, and tests.\r\n\r\n---\r\n\r\n### 2. Use Domain Outputs To Preserve Business Meaning\r\n\r\n- Use the `Domain Canvas` outputs to guide naming, how the implementation is split into clear business responsibilities, and how different backend systems are connected without exposing their differences.\r\n- Preserve the validated meanings of entities, attributes, statuses, and source-of-truth rules.\r\n- Avoid leaking backend-specific models or inconsistencies into the public API.\r\n\r\n---\r\n\r\n### 3. Use Journey Outputs To Preserve Critical Flows\r\n\r\n- Use the `Customer Journey Canvas` outputs to identify which user flows are most important to support first.\r\n- Use the `API Consumer Experience` outputs to keep the API understandable, predictable, and easy to integrate.\r\n- Let the agreed journey priorities decide which implementation paths need the highest reliability, lowest latency, clearest errors, and strongest operational focus.\r\n\r\n---\r\n\r\n### 4. Use Value Proposition Outputs To Preserve Consumer Value\r\n\r\n- Use the `API Value Proposition Canvas` outputs to keep the implementation focused on the agreed pains, gains, and API features.\r\n- Preserve the field meanings, behavior, and promises that made the API valuable in the earlier stations.\r\n- Ensure error handling, freshness, and naming support both the intended developer experience and the business use case.\r\n\r\n---\r\n\r\n### 5. Use Architecture Outputs To Shape Runtime Decisions\r\n\r\n- Use the `Business Impact Canvas` outputs to guide resilience, timeout, fallback, and degradation decisions.\r\n- Use the `Locations Canvas` outputs to guide network boundaries, trust boundaries, access paths, and deployment constraints.\r\n- Use the `Capacity Canvas` outputs to guide rate limits, caching, scaling, and peak-load behavior.\r\n- Use the `API Metrics And Analytics` guidance to decide what must be observed from the first implementation onward.\r\n\r\n---\r\n\r\n### 6. Use Interaction And Protocol Design Outputs To Shape Code Structure\r\n\r\n- Use the `Interaction Canvas` outputs to avoid implementing unsupported interaction styles too early.\r\n- Use the `REST`, `Event`, or `GraphQL` design outputs to shape protocol-specific request, response, and validation behavior.\r\n- Reflect the selected interaction style clearly in code structure, responsibilities, and testing strategy.\r\n\r\n---\r\n\r\n### 7. Use Audit Outputs To Improve Delivery Before Coding Goes Too Far\r\n\r\n- Use the audit findings to remove ambiguity before implementation spreads across the codebase.\r\n- Fix unclear request rules, missing validation, weak error contracts, and operational gaps early.\r\n- Treat audit as a design-improvement loop before production, not only as a final decision gate.\r\n\r\n---\r\n\r\n### 8. Apply The Guidance, Then Summarize\r\n\r\n- Apply this guidance to the current API and implementation plan.\r\n- Summarize the implications for code structure, request validation, source integration, security, monitoring and alerts, and testing.\r\n- Do not create a separate delivery artifact unless the team or user specifically needs one.\r\n",
              "draft": true
            },
            {
              "id": "api-testing-best-practices",
              "slug": "resources/api-testing-best-practices",
              "title": "API Testing Best Practices",
              "description": "Guidelines for implementing automated functional, performance, and security testing throughout the API lifecycle.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 133,
              "outcomes": [
                "Shared understanding of the purpose and use of API Testing Best Practices",
                "A consistent approach to applying API Testing Best Practices",
                "Improved application of the related practices"
              ],
              "steps": [
                "Test APIs for functionality, security, and performance using automated testing tools.",
                "Integrate functional and non-functional testing into the CI/CD pipeline to ensure APIs meet quality standards.",
                "Use automated testing tools to validate API functionality, security, and performance."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "apiops-CI-CD-for-apis",
              "slug": "resources/apiops-CI-CD-for-apis",
              "title": "APIOps CI/CD For APIs",
              "description": "Deployment guidance that integrates API lifecycle tasks—design, testing, governance—into continuous integration and delivery pipelines.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 140,
              "outcomes": [
                "Shared understanding of the purpose and use of APIOps CI/CD For APIs",
                "A consistent approach to applying APIOps CI/CD For APIs",
                "Improved application of the related practices"
              ],
              "steps": [
                "Use CI/CD pipelines to automate build, test, and deployment processes, ensuring consistent quality and traceability.",
                "Integrate automated tests into the CI/CD pipeline to ensure continuous validation of API quality.",
                "Implement deployment strategies (e.g., blue-green deployments, canary releases) to minimize risks during API releases.",
                "Establish a habit of reviewing metrics and planning continuous improvement activities."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "api-audit-checklist",
              "slug": "resources/api-audit-checklist",
              "title": "API Audit Checklist",
              "description": "A lifecycle-based checklist to verify API readiness across design, delivery, publishing, and compliance using defined audit criteria and evidence.",
              "category": "checklist",
              "icon": "check-box-outline",
              "order": 13,
              "outcomes": [
                "Shared understanding of the purpose and use of API Audit Checklist",
                "A consistent approach to applying API Audit Checklist",
                "Improved application of the related practices"
              ],
              "steps": [
                "Use the API Audit Checklist to ensure the API design meets functional and non-functional requirements, including security, performance, and compliance.",
                "Conduct audits to assess lifecycle coverage and verify that the API meets business, design, and operational standards.",
                "Ensure that documentation, security models, gateway configuration, and legal requirements are clearly defined, validated, and supported by evidence."
              ],
              "canvasId": null,
              "sourcePath": "src/snippets/api-audit-checklist.json",
              "sourceUrl": null,
              "contentMarkdown": "{\r\n  \"profiles\": {\r\n    \"read-only\": {\r\n      \"description\": \"API profile that is read-only and does not allow create, update, or delete operations.\"\r\n    },\r\n    \"full-crud\": {\r\n      \"description\": \"General API profile that allows create, update, and delete operations.\"\r\n    }\r\n  },\r\n  \"lifecycleStages\": [\r\n    {\r\n      \"id\": \"strategy\",\r\n      \"title\": \"Strategy\",\r\n      \"readinessLabel\": \"Strategy is Ready When...\",\r\n      \"order\": 1\r\n    },\r\n    {\r\n      \"id\": \"architecture\",\r\n      \"title\": \"Architecture\",\r\n      \"readinessLabel\": \"Architecture is Ready When...\",\r\n      \"order\": 2\r\n    },\r\n    {\r\n      \"id\": \"design\",\r\n      \"title\": \"Design\",\r\n      \"readinessLabel\": \"Design is Ready When...\",\r\n      \"order\": 3\r\n    },\r\n    {\r\n      \"id\": \"delivery\",\r\n      \"title\": \"Delivery\",\r\n      \"readinessLabel\": \"Delivery is Ready When...\",\r\n      \"order\": 4\r\n    },\r\n    {\r\n      \"id\": \"publishing\",\r\n      \"title\": \"Publishing\",\r\n      \"readinessLabel\": \"Publishing is Ready When...\",\r\n      \"order\": 5\r\n    },\r\n    {\r\n      \"id\": \"improving\",\r\n      \"title\": \"Improving\",\r\n      \"readinessLabel\": \"Improving is Ready When...\",\r\n      \"order\": 6\r\n    }\r\n  ],\r\n  \"stages\": [\r\n    {\r\n      \"id\": \"strategy\",\r\n      \"title\": \"Strategy\",\r\n      \"readinessLabel\": \"Strategy is Ready When...\",\r\n      \"order\": 1,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"based-on-clear-business-needs\",\r\n          \"label\": \"API is based on clear business needs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"strategy\",\r\n          \"producedByStation\": [\r\n            \"api-product-strategy\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"business-goals-defined\",\r\n            \"market-research-done\",\r\n            \"stakeholder-approval\",\r\n            \"metrics-feedback-available\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DOMAIN-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiBusinessModelCanvas\",\r\n            \"apiValuePropositionCanvas\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"design-artifact\",\r\n            \"documentation\",\r\n            \"research\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-product-strategy/apiValuePropositionCanvas.empty.json\",\r\n            \"specs/canvases/api-product-strategy/apiBusinessModelCanvas.empty.json\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"concept-items-audited\",\r\n          \"label\": \"All concept checklist items are audited\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"aggregate\",\r\n          \"check\": {\r\n            \"type\": \"stageCoverage\",\r\n            \"stageId\": \"strategy\"\r\n          },\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"strategy\",\r\n          \"producedByStation\": [\r\n            \"api-product-strategy\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"business-goals-defined\",\r\n            \"market-research-done\",\r\n            \"stakeholder-approval\",\r\n            \"metrics-feedback-available\",\r\n            \"api-opportunity-documented\",\r\n            \"api-reusability\",\r\n            \"value-prop-validated\",\r\n            \"consumer-segments-identified\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"report\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"audit/concept-review-report.json\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"architecture\",\r\n      \"title\": \"Architecture\",\r\n      \"readinessLabel\": \"Architecture is Ready When...\",\r\n      \"order\": 2,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"versioning-decided\",\r\n          \"label\": \"Versioning strategy decided and supported by gateway\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"architecture\",\r\n          \"producedByStation\": [\r\n            \"api-platform-architecture\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-roadmap-defined\",\r\n            \"api-reusability\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-VERSION-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"contract-first-design\",\r\n            \"api-versioning-best-practices\",\r\n            \"apiops-CI-CD-for-apis\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"ci-cd\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"docs/api/architecture/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"only-via-gateway\",\r\n          \"label\": \"Only accessible via API gateway\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"architecture\",\r\n          \"producedByStation\": [\r\n            \"api-platform-architecture\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-reusability\",\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-02\",\r\n            \"REST-CAPACITY-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"businessImpactCanvas\",\r\n            \"locationsCanvas\",\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"gateway-config\",\r\n            \"infra-config\",\r\n            \"security-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/architecture/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"rate-limits-enforced\",\r\n          \"label\": \"Rate limits are enforced\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"architecture\",\r\n          \"producedByStation\": [\r\n            \"api-platform-architecture\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-roadmap-defined\",\r\n            \"api-reusability\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CAPACITY-01\",\r\n            \"REST-OBS-01\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"capacityCanvas\",\r\n            \"api-security-best-practices\",\r\n            \"scalable-infrastructure-best-practices\",\r\n            \"api-metrics-and-analytics\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"gateway-config\",\r\n            \"runtime\",\r\n            \"monitoring\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-platform-architecture/capacityCanvas.empty.json\",\r\n            \"docs/api/architecture/README.md\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"design\",\r\n      \"title\": \"Design\",\r\n      \"readinessLabel\": \"Design is Ready When...\",\r\n      \"order\": 3,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"endpoint-descriptions-present\",\r\n          \"label\": \"Endpoints have business value and feature descriptions\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"operationDescriptions\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"value-prop-validated\",\r\n            \"api-opportunity-documented\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CX-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiValuePropositionCanvas\",\r\n            \"customerJourneyCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"design-artifact\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"specs/canvases/api-product-strategy/apiValuePropositionCanvas.empty.json\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"hides-raw-backend-data\",\r\n          \"label\": \"API hides raw backend data and is designed for shared use\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"hide-backend-discrepancies\",\r\n            \"design-reflects-business-value\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DOMAIN-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"interactionCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"design-artifact\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-product-strategy/domainCanvas.empty.json\",\r\n            \"specs/canvases/api-design/interactionCanvas.empty.json\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"design-consistent\",\r\n          \"label\": \"API design is consistent with other APIs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-platform-architecture\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"architecture-patterns-validated\",\r\n            \"api-reusability\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DOMAIN-02\",\r\n            \"REST-CX-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"documentation\",\r\n            \"design-artifact\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-design/restCanvas.empty.json\",\r\n            \"docs/api/design/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"descriptive-english-naming\",\r\n          \"label\": \"Data and attribute naming uses descriptive English\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"fieldNamesDescriptive\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-NAMING-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"mandatory-fields-specified\",\r\n          \"label\": \"Mandatory fields are specified\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"requiredFieldsPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-VALIDATION-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"contract\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"dates-use-iso\",\r\n          \"label\": \"Dates use ISO format with timezone\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"dateFormatTimezone\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DATA-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"general-data-uses-standard-values\",\r\n          \"label\": \"General data uses standard values\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"standardizedEnumsOrPatterns\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"design-reflects-business-value\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DATA-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"field-names-avoid-acronyms\",\r\n          \"label\": \"Field names avoid acronyms and use full words\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"avoidAcronyms\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-NAMING-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"create-returns-identifiers\",\r\n          \"label\": \"Creating new resources returns identifiers\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is read-only and does not create resources.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-201-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"paths-max-two-resources\",\r\n          \"label\": \"Endpoint paths contain max two resources or sub-resources\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"pathDepthMax\",\r\n            \"maxDepth\": 2\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PATH-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"examples-present\",\r\n          \"label\": \"Endpoints and attributes include examples\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"examplesPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CX-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"restCanvas\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"post-for-create-update\",\r\n          \"label\": \"POST is used for create or update\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose create or update operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"design-reflects-business-value\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-POST-01\",\r\n            \"REST-HTTP-PUT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"delete-for-remove\",\r\n          \"label\": \"DELETE is used to remove resources\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose delete operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-DELETE-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"get-no-request-body\",\r\n          \"label\": \"GET has no request body and returns content\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"getNoRequestBody\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-GET-01\",\r\n            \"REST-RESP-200-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"get-empty-returns-204\",\r\n          \"label\": \"GET returns 204 if response body is empty\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"The current contract returns content for all GET operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-204-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"post-returns-200\",\r\n          \"label\": \"POST returns 200 OK when updating\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose POST updates.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-200-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"post-returns-201\",\r\n          \"label\": \"POST returns 201 Created with ID on create\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose POST creates.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-201-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"delete-returns-204\",\r\n          \"label\": \"DELETE returns 204 on success\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose DELETE operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-204-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"400-errors-specific\",\r\n          \"label\": \"400 errors provide specific error information\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"errorResponsesSpecific\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-ERROR-400-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"restCanvas\",\r\n            \"api-audit-checklist\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"401-unauthorized\",\r\n          \"label\": \"401 Unauthorized for wrong credentials\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"The current public storefront contract is intentionally unauthenticated.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-ERROR-401-01\",\r\n            \"REST-SEC-01\",\r\n            \"REST-SEC-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"security-config\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"403-forbidden\",\r\n          \"label\": \"403 Forbidden for unauthorized operations\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"The current profile is public read-only and exposes no unauthorized operations.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-ERROR-403-01\",\r\n            \"REST-SEC-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"security-config\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"spec-contains-schemas\",\r\n          \"label\": \"Spec contains request and response schema\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"schemasPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CONTRACT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"contract-first-design\",\r\n            \"restCanvas\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"contract\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"pseudo-identifiers\",\r\n          \"label\": \"UUIDs or pseudo-identifiers instead of DB IDs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"opaqueIdentifiers\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"hide-backend-discrepancies\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-07\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"contract-first-design\",\r\n            \"api-security-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"no-sensitive-data-in-urls\",\r\n          \"label\": \"No sensitive data in URLs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"noSensitiveDataInPaths\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"hide-backend-discrepancies\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-06\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"contract-first-design\",\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"http-methods-match-resources\",\r\n          \"label\": \"HTTP methods only for intended resources\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"methodResourceConsistency\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-GET-01\",\r\n            \"REST-HTTP-POST-01\",\r\n            \"REST-HTTP-PUT-01\",\r\n            \"REST-HTTP-DELETE-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"delivery\",\r\n      \"title\": \"Delivery\",\r\n      \"readinessLabel\": \"Delivery is Ready When...\",\r\n      \"order\": 4,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"design-items-audited\",\r\n          \"label\": \"All prototype and design items are audited\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"aggregate\",\r\n          \"check\": {\r\n            \"type\": \"stageCoverage\",\r\n            \"stageId\": \"design\"\r\n          },\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"design-reflects-business-value\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"report\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"audit/production-readiness-review.json\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"spec-validated-on-change\",\r\n          \"label\": \"Spec validated on every change\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"validationWorkflowPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-audit-checklist\",\r\n            \"contract-first-design\",\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"api-testing-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"ci-cd\",\r\n            \"spec\",\r\n            \"test\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \".github/workflows/openapi-lint.yml\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"schema-and-examples-pass\",\r\n          \"label\": \"Schema and examples pass validation\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"examplesPassValidation\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"architecture-patterns-validated\",\r\n            \"api-contract-tested\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-01\",\r\n            \"REST-CONTRACT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"contract-first-design\",\r\n            \"api-audit-checklist\",\r\n            \"api-testing-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"test\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"uses-https\",\r\n          \"label\": \"Uses HTTPS or encrypted protocols\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-05\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"auth-protection\",\r\n          \"label\": \"Endpoints protected by authentication\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is intentionally public read-only.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-01\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"gateway-config\",\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"token-auth\",\r\n          \"label\": \"Token-based authentication\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is intentionally public read-only.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"csrf-protection\",\r\n          \"label\": \"Protected against CSRF\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is intentionally public read-only.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-08\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-development-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"code\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"inputs-auto-validated\",\r\n          \"label\": \"Inputs auto-validated by framework\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-VALIDATION-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-development-best-practices\",\r\n            \"contract-first-design\",\r\n            \"api-testing-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"code\",\r\n            \"test\",\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"docs/api/delivery/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"outputs-auto-escaped\",\r\n          \"label\": \"Outputs auto-escaped by framework\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"JSON APIs do not typically require output escaping in the same way as HTML rendering.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-development-best-practices\",\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"code\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"encryption-in-transit\",\r\n          \"label\": \"Encryption for data in transit and storage\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-05\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\",\r\n            \"api-metrics-and-analytics\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"infra-config\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"message-integrity\",\r\n          \"label\": \"Message integrity implemented\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-OBS-01\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"api-compliance-best-practices\",\r\n            \"api-metrics-and-analytics\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"monitoring\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/architecture/README.md\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"publishing\",\r\n      \"title\": \"Publishing\",\r\n      \"readinessLabel\": \"Publishing is Ready When...\",\r\n      \"order\": 5,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"published-via-api-management\",\r\n          \"label\": \"Published via API management\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"api-onboarding-best-practices\",\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"gateway-config\",\r\n            \"ci-cd\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \".github/workflows/openapi-lint.yml\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"visible-in-dev-portal\",\r\n          \"label\": \"Visible in developer portal\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-documentation-ready\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"api-community-engagement-strategies\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"documentation\",\r\n            \"runtime\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"docs-auto-generated\",\r\n          \"label\": \"Docs auto-generated from spec and schema\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\",\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-documentation-ready\",\r\n            \"api-ready-for-publishing\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CONTRACT-02\",\r\n            \"REST-PUBLISH-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"contract-first-design\",\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"api-onboarding-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"documentation\",\r\n            \"ci-cd\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"docs/api/audit/design-audit.read-only.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"spec-auto-updated\",\r\n          \"label\": \"Spec auto-updated to gateway and dev portal\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\",\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CONTRACT-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"contract-first-design\",\r\n            \"api-onboarding-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"ci-cd\",\r\n            \"gateway-config\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \".github/workflows/openapi-lint.yml\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"official-domain\",\r\n          \"label\": \"Published under official organization domain\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"documentation\",\r\n            \"runtime\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"improving\",\r\n      \"title\": \"Improving\",\r\n      \"readinessLabel\": \"Improving is Ready When...\",\r\n      \"order\": 6,\r\n      \"items\": []\r\n    }\r\n  ],\r\n  \"guidelines\": [\r\n    {\r\n      \"id\": \"REST-CONTRACT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST implement endpoints, parameters, request bodies, response bodies, and error responses as defined in the validated OpenAPI contract.\",\r\n      \"relatedAuditItems\": [\r\n        \"spec-contains-schemas\",\r\n        \"schema-and-examples-pass\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CONTRACT-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST keep the implementation, published OpenAPI description, gateway configuration, and developer portal documentation aligned on every change.\",\r\n      \"relatedAuditItems\": [\r\n        \"docs-auto-generated\",\r\n        \"spec-auto-updated\",\r\n        \"spec-validated-on-change\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-VALIDATION-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST validate path parameters, query parameters, headers, and JSON request bodies against the OpenAPI schema before business processing.\",\r\n      \"relatedAuditItems\": [\r\n        \"mandatory-fields-specified\",\r\n        \"400-errors-specific\",\r\n        \"inputs-auto-validated\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DOMAIN-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST expose business-oriented resources and attributes rather than raw backend tables, internal service payloads, or system-specific field names.\",\r\n      \"relatedAuditItems\": [\r\n        \"based-on-clear-business-needs\",\r\n        \"hides-raw-backend-data\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DOMAIN-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST preserve validated meanings of entities, attributes, statuses, and source-of-truth rules across all endpoints and operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"design-consistent\",\r\n        \"general-data-uses-standard-values\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-NAMING-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST use descriptive English names for resources and attributes.\",\r\n      \"relatedAuditItems\": [\r\n        \"descriptive-english-naming\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-NAMING-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST avoid unexplained acronyms in public field and resource names.\",\r\n      \"relatedAuditItems\": [\r\n        \"field-names-avoid-acronyms\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DATA-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST use ISO date-time values with timezone information where dates are exposed.\",\r\n      \"relatedAuditItems\": [\r\n        \"dates-use-iso\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DATA-02\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API SHOULD use standard codes, controlled vocabularies, and standardized value sets where applicable.\",\r\n      \"relatedAuditItems\": [\r\n        \"general-data-uses-standard-values\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API MUST describe the business value and feature intent of each endpoint or capability.\",\r\n      \"relatedAuditItems\": [\r\n        \"endpoint-descriptions-present\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API MUST include examples for endpoints, request bodies, response bodies, and key attributes.\",\r\n      \"relatedAuditItems\": [\r\n        \"examples-present\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-03\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API SHOULD use consistent pagination, filtering, sorting, and response conventions across resources.\",\r\n      \"relatedAuditItems\": [\r\n        \"design-consistent\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-GET-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use GET for safe read-only operations and MUST NOT define a request body for GET operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-no-request-body\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-POST-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use POST for resource creation and other non-idempotent operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"post-for-create-update\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-PUT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use PUT only for full resource replacement.\",\r\n      \"relatedAuditItems\": [\r\n        \"post-for-create-update\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-DELETE-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use DELETE to remove resources.\",\r\n      \"relatedAuditItems\": [\r\n        \"delete-for-remove\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PATH-01\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"resource-modeling\",\r\n      \"requirement\": \"The REST API SHOULD keep endpoint paths shallow and avoid more than two resource or sub-resource levels unless explicitly justified.\",\r\n      \"relatedAuditItems\": [\r\n        \"paths-max-two-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-200-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 200 OK for successful reads and updates that include a response body.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-no-request-body\",\r\n        \"post-returns-200\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-201-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 201 Created and the created resource identifier when a new resource is created.\",\r\n      \"relatedAuditItems\": [\r\n        \"create-returns-identifiers\",\r\n        \"post-returns-201\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-204-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 204 No Content for successful delete operations that do not return a body.\",\r\n      \"relatedAuditItems\": [\r\n        \"delete-returns-204\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-204-02\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API SHOULD return 204 No Content for successful operations that intentionally return no response body.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-empty-returns-204\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-400-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST define 400 Bad Request responses with specific and actionable validation error information.\",\r\n      \"relatedAuditItems\": [\r\n        \"400-errors-specific\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-401-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST return 401 Unauthorized for missing or invalid credentials.\",\r\n      \"relatedAuditItems\": [\r\n        \"401-unauthorized\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-403-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST return 403 Forbidden for authenticated clients lacking sufficient permission.\",\r\n      \"relatedAuditItems\": [\r\n        \"403-forbidden\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-VERSION-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"versioning\",\r\n      \"requirement\": \"The REST API MUST define a versioning strategy before production release, and the strategy MUST be supportable by the API gateway.\",\r\n      \"relatedAuditItems\": [\r\n        \"versioning-decided\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST require authentication for protected endpoints.\",\r\n      \"relatedAuditItems\": [\r\n        \"auth-protection\",\r\n        \"401-unauthorized\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST use token-based authentication or another approved modern authentication mechanism for protected endpoints.\",\r\n      \"relatedAuditItems\": [\r\n        \"token-auth\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-03\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST enforce object-level and function-level authorization on every protected operation.\",\r\n      \"relatedAuditItems\": [\r\n        \"401-unauthorized\",\r\n        \"403-forbidden\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-04\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST mitigate OWASP API risks including broken object level authorization, broken function level authorization, injection, and unrestricted resource consumption.\",\r\n      \"relatedAuditItems\": [\r\n        \"auth-protection\",\r\n        \"rate-limits-enforced\",\r\n        \"no-sensitive-data-in-urls\",\r\n        \"message-integrity\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-05\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST use HTTPS or another approved encrypted protocol for all traffic.\",\r\n      \"relatedAuditItems\": [\r\n        \"uses-https\",\r\n        \"encryption-in-transit\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-06\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST NOT expose sensitive information in URLs, query strings, logs, or unnecessary response fields.\",\r\n      \"relatedAuditItems\": [\r\n        \"no-sensitive-data-in-urls\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-07\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API SHOULD use UUIDs or other non-sequential public identifiers where direct database identifiers would increase exposure risk.\",\r\n      \"relatedAuditItems\": [\r\n        \"pseudo-identifiers\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-08\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST implement CSRF protection where relevant to the authentication model and client interaction pattern.\",\r\n      \"relatedAuditItems\": [\r\n        \"csrf-protection\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CAPACITY-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"resilience-capacity\",\r\n      \"requirement\": \"The REST API MUST define and enforce rate limits, throttling, or quotas according to capacity expectations.\",\r\n      \"relatedAuditItems\": [\r\n        \"rate-limits-enforced\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CAPACITY-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"resilience-capacity\",\r\n      \"requirement\": \"The REST API MUST implement resilience controls such as timeouts, fallback behavior, and degradation handling according to business impact.\",\r\n      \"relatedAuditItems\": [\r\n        \"only-via-gateway\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-OBS-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"observability\",\r\n      \"requirement\": \"The REST API MUST implement logs, metrics, and monitoring needed to observe validation failures, auth failures, traffic, latency, and dependency health.\",\r\n      \"relatedAuditItems\": [\r\n        \"rate-limits-enforced\",\r\n        \"message-integrity\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be published through an API management platform.\",\r\n      \"relatedAuditItems\": [\r\n        \"published-via-api-management\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be accessible only through approved API gateway paths and managed entry points.\",\r\n      \"relatedAuditItems\": [\r\n        \"only-via-gateway\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-03\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API SHOULD be visible in a developer portal with documentation generated from the contract.\",\r\n      \"relatedAuditItems\": [\r\n        \"visible-in-dev-portal\",\r\n        \"docs-auto-generated\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-04\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be published under an approved organizational domain.\",\r\n      \"relatedAuditItems\": [\r\n        \"official-domain\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-AUDIT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST validate the specification, schema, and examples on every change.\",\r\n      \"relatedAuditItems\": [\r\n        \"spec-validated-on-change\",\r\n        \"schema-and-examples-pass\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-AUDIT-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST pass concept, design, security, and production-readiness checks before release.\",\r\n      \"relatedAuditItems\": [\r\n        \"concept-items-audited\",\r\n        \"design-items-audited\"\r\n      ]\r\n    }\r\n  ]\r\n}\r\n",
              "draft": false
            },
            {
              "id": "api-compliance-best-practices",
              "slug": "resources/api-compliance-best-practices",
              "title": "API Compliance Best Practices",
              "description": "Ensure APIs meet legal, regulatory, and internal compliance through documentation, controls, and automated validations.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 104,
              "outcomes": [
                "Shared understanding of the purpose and use of API Compliance Best Practices",
                "A consistent approach to applying API Compliance Best Practices",
                "Improved application of the related practices"
              ],
              "steps": [
                "Document compliance measures and ensure they are communicated to stakeholders and consumers.",
                "Implement measures to ensure APIs comply with these requirements, including data encryption, access controls, and audit trails.",
                "Use checklists, linters, and testing tools to verify consistency and conformance with standards."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "consumerExperienceRequirementsCanvas",
              "slug": "resources/consumer-experience-requirements-canvas",
              "title": "Consumer Experience Requirements Canvas",
              "description": "A requirements canvas for consumer experience and non-functional needs that should guide the later architecture and implementation-style decision.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 3.2,
              "outcomes": [
                "Technology-agnostic consumer and service requirements",
                "Experience and non-functional needs captured before design starts",
                "Architecture implications documented for implementation-style selection"
              ],
              "steps": [
                "Capture consumer goals and usage context.",
                "Document availability, timeliness, volume, performance, data quality, and consistency expectations.",
                "Document security, privacy, onboarding, change, observability, support, and recovery expectations.",
                "Summarize what the requirements imply for possible implementation styles."
              ],
              "canvasId": "consumerExperienceRequirementsCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "api-onboarding-best-practices",
              "slug": "resources/api-onboarding-best-practices",
              "title": "API Onboarding Best Practices",
              "description": "Best practices to streamline API consumer onboarding journeys with step-by-step registration, discovery, and first-call guidance.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 121,
              "outcomes": [
                "Shared understanding of the purpose and use of API Onboarding Best Practices",
                "A consistent approach to applying API Onboarding Best Practices",
                "Improved application of the related practices"
              ],
              "steps": [
                "Define the API consumer journey from discovery to troubleshooting, identifying key touchpoints and pain points.",
                "Develop onboarding processes and resources to help API consumers understand how to use APIs effectively.",
                "Document how consumers find and use the API, including onboarding processes and registration."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            }
          ],
          "promptIds": [
            "api-designer:facilitate-station",
            "api-designer:use-resources",
            "api-designer:next-actions"
          ]
        },
        {
          "id": "governance-specialist",
          "stakeholderId": "governance-specialist",
          "title": "API Governance Owner",
          "summary": "Represents review, audit, and organization-wide governance practices for API quality and conformity.",
          "stakeholder": {
            "id": "governance-specialist",
            "sourceKey": "governance-specialist",
            "sourceStakeholderId": "governance-specialist",
            "title": "API Governance Owner",
            "description": "Represents review, audit, and organization-wide governance practices for API quality and conformity.",
            "involvement": ""
          },
          "cycles": [
            {
              "id": "capability-productization-cycle",
              "title": "Capability Productization Cycle",
              "description": "A cycle for turning business capabilities into reusable digital capabilities before selecting the implementation style."
            },
            {
              "id": "api-productization-cycle",
              "title": "API Productization Cycle",
              "description": "The API-focused APIOps Cycles journey for productizing, designing, delivering, publishing, and improving APIs."
            },
            {
              "id": "integration-productization-cycle",
              "title": "Integration Productization Cycle",
              "description": "A cycle for productizing reusable integration capabilities before selecting the implementation style."
            },
            {
              "id": "automation-cycle",
              "title": "Automation Cycle",
              "description": "A cycle for identifying, designing, delivering, enabling, and improving automation opportunities."
            }
          ],
          "stations": [
            {
              "id": "api-audit",
              "title": "Quality & Readiness Assurance",
              "description": "Audit the capability interface contract, controls, support model, observability, documentation, and lifecycle readiness before release."
            }
          ],
          "canvases": [],
          "decisions": [
            "Use the audit checklist as a reusable quality checklist for interface contract, documentation, security, performance, and compliance readiness.",
            "Use checklists, linters, and testing tools to verify consistency and conformance with standards.",
            "Collaborate with governance teams and domain experts to ensure the capability is ready for production.",
            "Use audit and compliance resources to verify that the capability is ready for controlled release and reuse.",
            "Reusable capabilities create operational, data, security, privacy, compliance, and consumer-impact risks. Readiness checks reduce surprises before release or production use."
          ],
          "outputs": [
            "Documented readiness for release and reuse",
            "Known gaps and mitigations before release",
            "Evidence for governance, compliance, support, and operational approval",
            "Reduced risk of issues in production",
            "audit-report",
            "compliance-report",
            "security-report",
            "test-report"
          ],
          "recommendedResources": [
            {
              "id": "api-audit-checklist",
              "slug": "resources/api-audit-checklist",
              "title": "API Audit Checklist",
              "description": "A lifecycle-based checklist to verify API readiness across design, delivery, publishing, and compliance using defined audit criteria and evidence.",
              "category": "checklist",
              "icon": "check-box-outline",
              "order": 13,
              "outcomes": [
                "Shared understanding of the purpose and use of API Audit Checklist",
                "A consistent approach to applying API Audit Checklist",
                "Improved application of the related practices"
              ],
              "steps": [
                "Use the API Audit Checklist to ensure the API design meets functional and non-functional requirements, including security, performance, and compliance.",
                "Conduct audits to assess lifecycle coverage and verify that the API meets business, design, and operational standards.",
                "Ensure that documentation, security models, gateway configuration, and legal requirements are clearly defined, validated, and supported by evidence."
              ],
              "canvasId": null,
              "sourcePath": "src/snippets/api-audit-checklist.json",
              "sourceUrl": null,
              "contentMarkdown": "{\r\n  \"profiles\": {\r\n    \"read-only\": {\r\n      \"description\": \"API profile that is read-only and does not allow create, update, or delete operations.\"\r\n    },\r\n    \"full-crud\": {\r\n      \"description\": \"General API profile that allows create, update, and delete operations.\"\r\n    }\r\n  },\r\n  \"lifecycleStages\": [\r\n    {\r\n      \"id\": \"strategy\",\r\n      \"title\": \"Strategy\",\r\n      \"readinessLabel\": \"Strategy is Ready When...\",\r\n      \"order\": 1\r\n    },\r\n    {\r\n      \"id\": \"architecture\",\r\n      \"title\": \"Architecture\",\r\n      \"readinessLabel\": \"Architecture is Ready When...\",\r\n      \"order\": 2\r\n    },\r\n    {\r\n      \"id\": \"design\",\r\n      \"title\": \"Design\",\r\n      \"readinessLabel\": \"Design is Ready When...\",\r\n      \"order\": 3\r\n    },\r\n    {\r\n      \"id\": \"delivery\",\r\n      \"title\": \"Delivery\",\r\n      \"readinessLabel\": \"Delivery is Ready When...\",\r\n      \"order\": 4\r\n    },\r\n    {\r\n      \"id\": \"publishing\",\r\n      \"title\": \"Publishing\",\r\n      \"readinessLabel\": \"Publishing is Ready When...\",\r\n      \"order\": 5\r\n    },\r\n    {\r\n      \"id\": \"improving\",\r\n      \"title\": \"Improving\",\r\n      \"readinessLabel\": \"Improving is Ready When...\",\r\n      \"order\": 6\r\n    }\r\n  ],\r\n  \"stages\": [\r\n    {\r\n      \"id\": \"strategy\",\r\n      \"title\": \"Strategy\",\r\n      \"readinessLabel\": \"Strategy is Ready When...\",\r\n      \"order\": 1,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"based-on-clear-business-needs\",\r\n          \"label\": \"API is based on clear business needs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"strategy\",\r\n          \"producedByStation\": [\r\n            \"api-product-strategy\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"business-goals-defined\",\r\n            \"market-research-done\",\r\n            \"stakeholder-approval\",\r\n            \"metrics-feedback-available\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DOMAIN-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiBusinessModelCanvas\",\r\n            \"apiValuePropositionCanvas\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"design-artifact\",\r\n            \"documentation\",\r\n            \"research\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-product-strategy/apiValuePropositionCanvas.empty.json\",\r\n            \"specs/canvases/api-product-strategy/apiBusinessModelCanvas.empty.json\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"concept-items-audited\",\r\n          \"label\": \"All concept checklist items are audited\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"aggregate\",\r\n          \"check\": {\r\n            \"type\": \"stageCoverage\",\r\n            \"stageId\": \"strategy\"\r\n          },\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"strategy\",\r\n          \"producedByStation\": [\r\n            \"api-product-strategy\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"business-goals-defined\",\r\n            \"market-research-done\",\r\n            \"stakeholder-approval\",\r\n            \"metrics-feedback-available\",\r\n            \"api-opportunity-documented\",\r\n            \"api-reusability\",\r\n            \"value-prop-validated\",\r\n            \"consumer-segments-identified\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"report\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"audit/concept-review-report.json\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"architecture\",\r\n      \"title\": \"Architecture\",\r\n      \"readinessLabel\": \"Architecture is Ready When...\",\r\n      \"order\": 2,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"versioning-decided\",\r\n          \"label\": \"Versioning strategy decided and supported by gateway\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"architecture\",\r\n          \"producedByStation\": [\r\n            \"api-platform-architecture\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-roadmap-defined\",\r\n            \"api-reusability\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-VERSION-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"contract-first-design\",\r\n            \"api-versioning-best-practices\",\r\n            \"apiops-CI-CD-for-apis\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"ci-cd\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"docs/api/architecture/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"only-via-gateway\",\r\n          \"label\": \"Only accessible via API gateway\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"architecture\",\r\n          \"producedByStation\": [\r\n            \"api-platform-architecture\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-reusability\",\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-02\",\r\n            \"REST-CAPACITY-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"businessImpactCanvas\",\r\n            \"locationsCanvas\",\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"gateway-config\",\r\n            \"infra-config\",\r\n            \"security-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/architecture/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"rate-limits-enforced\",\r\n          \"label\": \"Rate limits are enforced\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"architecture\",\r\n          \"producedByStation\": [\r\n            \"api-platform-architecture\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-roadmap-defined\",\r\n            \"api-reusability\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CAPACITY-01\",\r\n            \"REST-OBS-01\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"capacityCanvas\",\r\n            \"api-security-best-practices\",\r\n            \"scalable-infrastructure-best-practices\",\r\n            \"api-metrics-and-analytics\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"gateway-config\",\r\n            \"runtime\",\r\n            \"monitoring\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-platform-architecture/capacityCanvas.empty.json\",\r\n            \"docs/api/architecture/README.md\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"design\",\r\n      \"title\": \"Design\",\r\n      \"readinessLabel\": \"Design is Ready When...\",\r\n      \"order\": 3,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"endpoint-descriptions-present\",\r\n          \"label\": \"Endpoints have business value and feature descriptions\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"operationDescriptions\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"value-prop-validated\",\r\n            \"api-opportunity-documented\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CX-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiValuePropositionCanvas\",\r\n            \"customerJourneyCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"design-artifact\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"specs/canvases/api-product-strategy/apiValuePropositionCanvas.empty.json\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"hides-raw-backend-data\",\r\n          \"label\": \"API hides raw backend data and is designed for shared use\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"hide-backend-discrepancies\",\r\n            \"design-reflects-business-value\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DOMAIN-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"interactionCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"design-artifact\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-product-strategy/domainCanvas.empty.json\",\r\n            \"specs/canvases/api-design/interactionCanvas.empty.json\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"design-consistent\",\r\n          \"label\": \"API design is consistent with other APIs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-platform-architecture\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"architecture-patterns-validated\",\r\n            \"api-reusability\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DOMAIN-02\",\r\n            \"REST-CX-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"documentation\",\r\n            \"design-artifact\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-design/restCanvas.empty.json\",\r\n            \"docs/api/design/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"descriptive-english-naming\",\r\n          \"label\": \"Data and attribute naming uses descriptive English\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"fieldNamesDescriptive\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-NAMING-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"mandatory-fields-specified\",\r\n          \"label\": \"Mandatory fields are specified\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"requiredFieldsPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-VALIDATION-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"contract\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"dates-use-iso\",\r\n          \"label\": \"Dates use ISO format with timezone\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"dateFormatTimezone\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DATA-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"general-data-uses-standard-values\",\r\n          \"label\": \"General data uses standard values\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"standardizedEnumsOrPatterns\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"design-reflects-business-value\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DATA-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"field-names-avoid-acronyms\",\r\n          \"label\": \"Field names avoid acronyms and use full words\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"avoidAcronyms\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-NAMING-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"create-returns-identifiers\",\r\n          \"label\": \"Creating new resources returns identifiers\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is read-only and does not create resources.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-201-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"paths-max-two-resources\",\r\n          \"label\": \"Endpoint paths contain max two resources or sub-resources\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"pathDepthMax\",\r\n            \"maxDepth\": 2\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PATH-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"examples-present\",\r\n          \"label\": \"Endpoints and attributes include examples\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"examplesPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CX-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"restCanvas\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"post-for-create-update\",\r\n          \"label\": \"POST is used for create or update\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose create or update operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"design-reflects-business-value\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-POST-01\",\r\n            \"REST-HTTP-PUT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"delete-for-remove\",\r\n          \"label\": \"DELETE is used to remove resources\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose delete operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-DELETE-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"get-no-request-body\",\r\n          \"label\": \"GET has no request body and returns content\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"getNoRequestBody\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-GET-01\",\r\n            \"REST-RESP-200-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"get-empty-returns-204\",\r\n          \"label\": \"GET returns 204 if response body is empty\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"The current contract returns content for all GET operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-204-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"post-returns-200\",\r\n          \"label\": \"POST returns 200 OK when updating\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose POST updates.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-200-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"post-returns-201\",\r\n          \"label\": \"POST returns 201 Created with ID on create\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose POST creates.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-201-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"delete-returns-204\",\r\n          \"label\": \"DELETE returns 204 on success\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose DELETE operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-204-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"400-errors-specific\",\r\n          \"label\": \"400 errors provide specific error information\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"errorResponsesSpecific\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-ERROR-400-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"restCanvas\",\r\n            \"api-audit-checklist\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"401-unauthorized\",\r\n          \"label\": \"401 Unauthorized for wrong credentials\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"The current public storefront contract is intentionally unauthenticated.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-ERROR-401-01\",\r\n            \"REST-SEC-01\",\r\n            \"REST-SEC-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"security-config\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"403-forbidden\",\r\n          \"label\": \"403 Forbidden for unauthorized operations\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"The current profile is public read-only and exposes no unauthorized operations.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-ERROR-403-01\",\r\n            \"REST-SEC-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"security-config\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"spec-contains-schemas\",\r\n          \"label\": \"Spec contains request and response schema\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"schemasPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CONTRACT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"contract-first-design\",\r\n            \"restCanvas\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"contract\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"pseudo-identifiers\",\r\n          \"label\": \"UUIDs or pseudo-identifiers instead of DB IDs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"opaqueIdentifiers\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"hide-backend-discrepancies\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-07\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"contract-first-design\",\r\n            \"api-security-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"no-sensitive-data-in-urls\",\r\n          \"label\": \"No sensitive data in URLs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"noSensitiveDataInPaths\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"hide-backend-discrepancies\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-06\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"contract-first-design\",\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"http-methods-match-resources\",\r\n          \"label\": \"HTTP methods only for intended resources\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"methodResourceConsistency\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-GET-01\",\r\n            \"REST-HTTP-POST-01\",\r\n            \"REST-HTTP-PUT-01\",\r\n            \"REST-HTTP-DELETE-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"delivery\",\r\n      \"title\": \"Delivery\",\r\n      \"readinessLabel\": \"Delivery is Ready When...\",\r\n      \"order\": 4,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"design-items-audited\",\r\n          \"label\": \"All prototype and design items are audited\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"aggregate\",\r\n          \"check\": {\r\n            \"type\": \"stageCoverage\",\r\n            \"stageId\": \"design\"\r\n          },\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"design-reflects-business-value\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"report\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"audit/production-readiness-review.json\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"spec-validated-on-change\",\r\n          \"label\": \"Spec validated on every change\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"validationWorkflowPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-audit-checklist\",\r\n            \"contract-first-design\",\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"api-testing-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"ci-cd\",\r\n            \"spec\",\r\n            \"test\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \".github/workflows/openapi-lint.yml\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"schema-and-examples-pass\",\r\n          \"label\": \"Schema and examples pass validation\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"examplesPassValidation\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"architecture-patterns-validated\",\r\n            \"api-contract-tested\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-01\",\r\n            \"REST-CONTRACT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"contract-first-design\",\r\n            \"api-audit-checklist\",\r\n            \"api-testing-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"test\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"uses-https\",\r\n          \"label\": \"Uses HTTPS or encrypted protocols\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-05\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"auth-protection\",\r\n          \"label\": \"Endpoints protected by authentication\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is intentionally public read-only.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-01\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"gateway-config\",\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"token-auth\",\r\n          \"label\": \"Token-based authentication\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is intentionally public read-only.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"csrf-protection\",\r\n          \"label\": \"Protected against CSRF\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is intentionally public read-only.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-08\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-development-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"code\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"inputs-auto-validated\",\r\n          \"label\": \"Inputs auto-validated by framework\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-VALIDATION-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-development-best-practices\",\r\n            \"contract-first-design\",\r\n            \"api-testing-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"code\",\r\n            \"test\",\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"docs/api/delivery/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"outputs-auto-escaped\",\r\n          \"label\": \"Outputs auto-escaped by framework\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"JSON APIs do not typically require output escaping in the same way as HTML rendering.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-development-best-practices\",\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"code\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"encryption-in-transit\",\r\n          \"label\": \"Encryption for data in transit and storage\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-05\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\",\r\n            \"api-metrics-and-analytics\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"infra-config\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"message-integrity\",\r\n          \"label\": \"Message integrity implemented\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-OBS-01\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"api-compliance-best-practices\",\r\n            \"api-metrics-and-analytics\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"monitoring\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/architecture/README.md\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"publishing\",\r\n      \"title\": \"Publishing\",\r\n      \"readinessLabel\": \"Publishing is Ready When...\",\r\n      \"order\": 5,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"published-via-api-management\",\r\n          \"label\": \"Published via API management\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"api-onboarding-best-practices\",\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"gateway-config\",\r\n            \"ci-cd\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \".github/workflows/openapi-lint.yml\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"visible-in-dev-portal\",\r\n          \"label\": \"Visible in developer portal\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-documentation-ready\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"api-community-engagement-strategies\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"documentation\",\r\n            \"runtime\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"docs-auto-generated\",\r\n          \"label\": \"Docs auto-generated from spec and schema\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\",\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-documentation-ready\",\r\n            \"api-ready-for-publishing\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CONTRACT-02\",\r\n            \"REST-PUBLISH-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"contract-first-design\",\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"api-onboarding-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"documentation\",\r\n            \"ci-cd\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"docs/api/audit/design-audit.read-only.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"spec-auto-updated\",\r\n          \"label\": \"Spec auto-updated to gateway and dev portal\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\",\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CONTRACT-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"contract-first-design\",\r\n            \"api-onboarding-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"ci-cd\",\r\n            \"gateway-config\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \".github/workflows/openapi-lint.yml\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"official-domain\",\r\n          \"label\": \"Published under official organization domain\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"documentation\",\r\n            \"runtime\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"improving\",\r\n      \"title\": \"Improving\",\r\n      \"readinessLabel\": \"Improving is Ready When...\",\r\n      \"order\": 6,\r\n      \"items\": []\r\n    }\r\n  ],\r\n  \"guidelines\": [\r\n    {\r\n      \"id\": \"REST-CONTRACT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST implement endpoints, parameters, request bodies, response bodies, and error responses as defined in the validated OpenAPI contract.\",\r\n      \"relatedAuditItems\": [\r\n        \"spec-contains-schemas\",\r\n        \"schema-and-examples-pass\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CONTRACT-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST keep the implementation, published OpenAPI description, gateway configuration, and developer portal documentation aligned on every change.\",\r\n      \"relatedAuditItems\": [\r\n        \"docs-auto-generated\",\r\n        \"spec-auto-updated\",\r\n        \"spec-validated-on-change\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-VALIDATION-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST validate path parameters, query parameters, headers, and JSON request bodies against the OpenAPI schema before business processing.\",\r\n      \"relatedAuditItems\": [\r\n        \"mandatory-fields-specified\",\r\n        \"400-errors-specific\",\r\n        \"inputs-auto-validated\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DOMAIN-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST expose business-oriented resources and attributes rather than raw backend tables, internal service payloads, or system-specific field names.\",\r\n      \"relatedAuditItems\": [\r\n        \"based-on-clear-business-needs\",\r\n        \"hides-raw-backend-data\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DOMAIN-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST preserve validated meanings of entities, attributes, statuses, and source-of-truth rules across all endpoints and operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"design-consistent\",\r\n        \"general-data-uses-standard-values\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-NAMING-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST use descriptive English names for resources and attributes.\",\r\n      \"relatedAuditItems\": [\r\n        \"descriptive-english-naming\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-NAMING-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST avoid unexplained acronyms in public field and resource names.\",\r\n      \"relatedAuditItems\": [\r\n        \"field-names-avoid-acronyms\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DATA-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST use ISO date-time values with timezone information where dates are exposed.\",\r\n      \"relatedAuditItems\": [\r\n        \"dates-use-iso\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DATA-02\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API SHOULD use standard codes, controlled vocabularies, and standardized value sets where applicable.\",\r\n      \"relatedAuditItems\": [\r\n        \"general-data-uses-standard-values\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API MUST describe the business value and feature intent of each endpoint or capability.\",\r\n      \"relatedAuditItems\": [\r\n        \"endpoint-descriptions-present\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API MUST include examples for endpoints, request bodies, response bodies, and key attributes.\",\r\n      \"relatedAuditItems\": [\r\n        \"examples-present\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-03\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API SHOULD use consistent pagination, filtering, sorting, and response conventions across resources.\",\r\n      \"relatedAuditItems\": [\r\n        \"design-consistent\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-GET-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use GET for safe read-only operations and MUST NOT define a request body for GET operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-no-request-body\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-POST-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use POST for resource creation and other non-idempotent operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"post-for-create-update\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-PUT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use PUT only for full resource replacement.\",\r\n      \"relatedAuditItems\": [\r\n        \"post-for-create-update\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-DELETE-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use DELETE to remove resources.\",\r\n      \"relatedAuditItems\": [\r\n        \"delete-for-remove\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PATH-01\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"resource-modeling\",\r\n      \"requirement\": \"The REST API SHOULD keep endpoint paths shallow and avoid more than two resource or sub-resource levels unless explicitly justified.\",\r\n      \"relatedAuditItems\": [\r\n        \"paths-max-two-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-200-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 200 OK for successful reads and updates that include a response body.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-no-request-body\",\r\n        \"post-returns-200\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-201-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 201 Created and the created resource identifier when a new resource is created.\",\r\n      \"relatedAuditItems\": [\r\n        \"create-returns-identifiers\",\r\n        \"post-returns-201\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-204-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 204 No Content for successful delete operations that do not return a body.\",\r\n      \"relatedAuditItems\": [\r\n        \"delete-returns-204\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-204-02\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API SHOULD return 204 No Content for successful operations that intentionally return no response body.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-empty-returns-204\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-400-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST define 400 Bad Request responses with specific and actionable validation error information.\",\r\n      \"relatedAuditItems\": [\r\n        \"400-errors-specific\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-401-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST return 401 Unauthorized for missing or invalid credentials.\",\r\n      \"relatedAuditItems\": [\r\n        \"401-unauthorized\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-403-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST return 403 Forbidden for authenticated clients lacking sufficient permission.\",\r\n      \"relatedAuditItems\": [\r\n        \"403-forbidden\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-VERSION-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"versioning\",\r\n      \"requirement\": \"The REST API MUST define a versioning strategy before production release, and the strategy MUST be supportable by the API gateway.\",\r\n      \"relatedAuditItems\": [\r\n        \"versioning-decided\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST require authentication for protected endpoints.\",\r\n      \"relatedAuditItems\": [\r\n        \"auth-protection\",\r\n        \"401-unauthorized\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST use token-based authentication or another approved modern authentication mechanism for protected endpoints.\",\r\n      \"relatedAuditItems\": [\r\n        \"token-auth\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-03\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST enforce object-level and function-level authorization on every protected operation.\",\r\n      \"relatedAuditItems\": [\r\n        \"401-unauthorized\",\r\n        \"403-forbidden\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-04\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST mitigate OWASP API risks including broken object level authorization, broken function level authorization, injection, and unrestricted resource consumption.\",\r\n      \"relatedAuditItems\": [\r\n        \"auth-protection\",\r\n        \"rate-limits-enforced\",\r\n        \"no-sensitive-data-in-urls\",\r\n        \"message-integrity\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-05\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST use HTTPS or another approved encrypted protocol for all traffic.\",\r\n      \"relatedAuditItems\": [\r\n        \"uses-https\",\r\n        \"encryption-in-transit\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-06\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST NOT expose sensitive information in URLs, query strings, logs, or unnecessary response fields.\",\r\n      \"relatedAuditItems\": [\r\n        \"no-sensitive-data-in-urls\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-07\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API SHOULD use UUIDs or other non-sequential public identifiers where direct database identifiers would increase exposure risk.\",\r\n      \"relatedAuditItems\": [\r\n        \"pseudo-identifiers\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-08\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST implement CSRF protection where relevant to the authentication model and client interaction pattern.\",\r\n      \"relatedAuditItems\": [\r\n        \"csrf-protection\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CAPACITY-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"resilience-capacity\",\r\n      \"requirement\": \"The REST API MUST define and enforce rate limits, throttling, or quotas according to capacity expectations.\",\r\n      \"relatedAuditItems\": [\r\n        \"rate-limits-enforced\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CAPACITY-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"resilience-capacity\",\r\n      \"requirement\": \"The REST API MUST implement resilience controls such as timeouts, fallback behavior, and degradation handling according to business impact.\",\r\n      \"relatedAuditItems\": [\r\n        \"only-via-gateway\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-OBS-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"observability\",\r\n      \"requirement\": \"The REST API MUST implement logs, metrics, and monitoring needed to observe validation failures, auth failures, traffic, latency, and dependency health.\",\r\n      \"relatedAuditItems\": [\r\n        \"rate-limits-enforced\",\r\n        \"message-integrity\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be published through an API management platform.\",\r\n      \"relatedAuditItems\": [\r\n        \"published-via-api-management\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be accessible only through approved API gateway paths and managed entry points.\",\r\n      \"relatedAuditItems\": [\r\n        \"only-via-gateway\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-03\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API SHOULD be visible in a developer portal with documentation generated from the contract.\",\r\n      \"relatedAuditItems\": [\r\n        \"visible-in-dev-portal\",\r\n        \"docs-auto-generated\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-04\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be published under an approved organizational domain.\",\r\n      \"relatedAuditItems\": [\r\n        \"official-domain\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-AUDIT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST validate the specification, schema, and examples on every change.\",\r\n      \"relatedAuditItems\": [\r\n        \"spec-validated-on-change\",\r\n        \"schema-and-examples-pass\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-AUDIT-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST pass concept, design, security, and production-readiness checks before release.\",\r\n      \"relatedAuditItems\": [\r\n        \"concept-items-audited\",\r\n        \"design-items-audited\"\r\n      ]\r\n    }\r\n  ]\r\n}\r\n",
              "draft": false
            },
            {
              "id": "api-compliance-best-practices",
              "slug": "resources/api-compliance-best-practices",
              "title": "API Compliance Best Practices",
              "description": "Ensure APIs meet legal, regulatory, and internal compliance through documentation, controls, and automated validations.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 104,
              "outcomes": [
                "Shared understanding of the purpose and use of API Compliance Best Practices",
                "A consistent approach to applying API Compliance Best Practices",
                "Improved application of the related practices"
              ],
              "steps": [
                "Document compliance measures and ensure they are communicated to stakeholders and consumers.",
                "Implement measures to ensure APIs comply with these requirements, including data encryption, access controls, and audit trails.",
                "Use checklists, linters, and testing tools to verify consistency and conformance with standards."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "automation-readiness-checklist",
              "slug": "resources/automation-readiness-checklist",
              "title": "Automation Readiness Checklist",
              "description": "A checklist for validating automation workflow, controls, risk, compliance, human oversight, testing evidence, rollback, operations, and release readiness.",
              "category": "checklist",
              "icon": "check-box-outline",
              "order": 187,
              "outcomes": [
                "Documented automation readiness",
                "Known readiness gaps and mitigations before release",
                "Evidence for quality, risk, compliance, oversight, and operational approval"
              ],
              "steps": [
                "Review workflow design, business rules, controls, access, data handling, and exception paths.",
                "Verify testing evidence, rollback procedures, supervision model, and support readiness.",
                "Confirm ownership, runbooks, monitoring, change controls, and release approval.",
                "Record unresolved gaps, decisions, and accepted risks before release."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            }
          ],
          "promptIds": [
            "governance-specialist:facilitate-station",
            "governance-specialist:use-resources",
            "governance-specialist:next-actions"
          ]
        },
        {
          "id": "api-product-owner",
          "stakeholderId": "api-product-owner",
          "title": "API Product Owner",
          "summary": "Drives the API opportunity, prioritization, and product-level decisions across the lifecycle.",
          "stakeholder": {
            "id": "api-product-owner",
            "sourceKey": "api-product-owner",
            "sourceStakeholderId": "api-product-owner",
            "title": "API Product Owner",
            "description": "Drives the API opportunity, prioritization, and product-level decisions across the lifecycle.",
            "involvement": ""
          },
          "cycles": [
            {
              "id": "capability-productization-cycle",
              "title": "Capability Productization Cycle",
              "description": "A cycle for turning business capabilities into reusable digital capabilities before selecting the implementation style."
            },
            {
              "id": "api-productization-cycle",
              "title": "API Productization Cycle",
              "description": "The API-focused APIOps Cycles journey for productizing, designing, delivering, publishing, and improving APIs."
            },
            {
              "id": "integration-productization-cycle",
              "title": "Integration Productization Cycle",
              "description": "A cycle for productizing reusable integration capabilities before selecting the implementation style."
            }
          ],
          "stations": [
            {
              "id": "api-platform-architecture",
              "title": "Architecture & Platform Decisions",
              "description": "Use requirements and constraints to decide the right architecture pattern and enabling platform capabilities."
            },
            {
              "id": "api-design",
              "title": "Solution & Interface Design",
              "description": "Design the interface contract and interaction model after the architecture choice is justified."
            },
            {
              "id": "api-product-strategy",
              "title": "Strategy",
              "description": "Frame the business need as a reusable capability before choosing the implementation style."
            },
            {
              "id": "api-consumer-experience",
              "title": "Consumer Requirements & Onboarding",
              "description": "Capture consumer onboarding, standards, non-functional requirements, service expectations, constraints, security needs, allowed protocols, data freshness, SLAs, observability, recovery, adoption requirements, and producer responsibilities."
            },
            {
              "id": "api-delivery",
              "title": "Delivery & Operations",
              "description": "Deliver the selected implementation style with appropriate engineering, testing, security, automation, and operational practices."
            },
            {
              "id": "api-audit",
              "title": "Quality & Readiness Assurance",
              "description": "Audit the capability interface contract, controls, support model, observability, documentation, and lifecycle readiness before release."
            },
            {
              "id": "api-publishing",
              "title": "Publishing & Enablement",
              "description": "Publish reusable capability information so consumers can discover, request, onboard, use, and get support."
            },
            {
              "id": "monitoring-and-improving",
              "title": "Monitoring & Improvement",
              "description": "Monitor usage, reliability, data quality, consumer outcomes, operational cost, and reuse opportunities after release."
            }
          ],
          "canvases": [
            {
              "id": "businessImpactCanvas",
              "title": "Business Impact Canvas"
            },
            {
              "id": "locationsCanvas",
              "title": "Locations Canvas"
            },
            {
              "id": "capacityCanvas",
              "title": "Capacity Canvas"
            },
            {
              "id": "domainCanvas",
              "title": "Domain Canvas"
            },
            {
              "id": "interactionCanvas",
              "title": "Interaction Canvas"
            },
            {
              "id": "customerJourneyCanvas",
              "title": "Customer Journey Canvas"
            },
            {
              "id": "capabilityValuePropositionCanvas",
              "title": "Capability Value Proposition Canvas"
            },
            {
              "id": "capabilityBusinessModelCanvas",
              "title": "Capability Business Model Canvas"
            },
            {
              "id": "consumerExperienceRequirementsCanvas",
              "title": "Consumer Experience Requirements Canvas"
            },
            {
              "id": "restCanvas",
              "title": "REST Canvas"
            },
            {
              "id": "eventCanvas",
              "title": "Event Canvas"
            },
            {
              "id": "graphqlCanvas",
              "title": "GraphQL Canvas"
            },
            {
              "id": "apiValuePropositionCanvas",
              "title": "API Value Proposition Canvas"
            },
            {
              "id": "apiBusinessModelCanvas",
              "title": "API Business Model Canvas"
            }
          ],
          "decisions": [
            "Use the Business Impact Canvas to identify availability, security, and data risks that influence architecture options.",
            "Use the Locations Canvas to capture geopolitical, regulatory, network, residency, and trust-boundary constraints.",
            "Use the Capacity Canvas to capture current and future volumes, peaks, latency, caching, rate limiting, and scaling expectations.",
            "Use metrics and analytics guidance to define how the chosen capability will be monitored and improved.",
            "Compare viable architecture styles against the gathered requirements and document the selected pattern and rationale.",
            "Architecture choices should follow from evidence about business impact, locations, trust boundaries, capacity, latency, data ownership, consistency, operability, security, privacy, governance, and cost."
          ],
          "outputs": [
            "A justified architecture choice",
            "Documented risks, locations, capacity, security, privacy, and operability constraints",
            "Clear rationale for API, event, file, stream, data product, direct integration, or hybrid implementation style",
            "architecture-decision",
            "documentation",
            "platform-config",
            "metrics",
            "A validated interface contract for the selected implementation style"
          ],
          "recommendedResources": [
            {
              "id": "businessImpactCanvas",
              "slug": "resources/business-impact-canvas",
              "title": "Business Impact Canvas",
              "description": "Identify business, availability, security, data, compliance, and operational risks that should shape architecture and platform decisions.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 4,
              "outcomes": [
                "Documented business and operational impact assessment",
                "Prioritized risks and mitigation actions",
                "Evidence for architecture and platform decisions"
              ],
              "steps": [
                "Availability Risks: Identify risks and impacts.",
                "Ways to Mitigate Availability Risks: Define mitigation measures.",
                "Security Risks: Document security-related risks.",
                "Ways to Mitigate Security Risks: Propose strategies to mitigate security risks.",
                "Data Risks: Identify risks to data accuracy or availability.",
                "Ways to Mitigate Data Risks: Plan strategies to address data risks."
              ],
              "canvasId": "businessImpactCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "locationsCanvas",
              "slug": "resources/location-canvas",
              "title": "Location Canvas",
              "description": "Map consumer, producer, system, data, network, regulatory, and trust-boundary locations to ensure compliance and performance across regions.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 6,
              "outcomes": [
                "Documented location, residency, network, and regulatory requirements",
                "Regional performance and accessibility constraints identified",
                "Data residency, trust boundaries, and applicable regulations clarified"
              ],
              "steps": [
                "Map locations of producers, source systems, platforms, and consumers.",
                "Document where consumers are located.",
                "Identify applicable regulations.",
                "Document where data must reside.",
                "Ensure the capability is accessible in all intended network regions.",
                "Validate network performance across regions."
              ],
              "canvasId": "locationsCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capacityCanvas",
              "slug": "resources/capacity-canvas",
              "title": "Capacity Canvas",
              "description": "Plan capacity for current and future demand, including volumes, peaks, latency, availability, scaling, caching, and rate limits for the selected capability and implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 7,
              "outcomes": [
                "Capacity requirements aligned with expected business demand",
                "Peak-load, availability, and growth assumptions documented",
                "Scaling, caching, and rate-limiting decisions defined"
              ],
              "steps": [
                "Document current business volumes",
                "Forecast future consumption trends",
                "Plan for peak load and availability requirements",
                "Define caching and rate-limiting strategies",
                "Propose scaling strategies"
              ],
              "canvasId": "capacityCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "domainCanvas",
              "slug": "resources/domain-canvas",
              "title": "Domain Canvas",
              "description": "A modeling tool to define and communicate the key entities and relationships in your domain, ensuring semantic consistency across capabilities, integrations, APIs, data products, and services.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 152,
              "outcomes": [
                "Shared domain model and terminology",
                "Core entities, relationships, rules, and ownership clarified",
                "Semantic consistency across capabilities, integrations, APIs, data products, and services"
              ],
              "steps": [
                "Define core entities, their attributes, and relationships to create a shared conceptual understanding across capabilities, integrations, APIs, data products, and services."
              ],
              "canvasId": "domainCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "interactionCanvas",
              "slug": "resources/interaction-canvas",
              "title": "Interaction Canvas",
              "description": "Define interactions, workflows, inputs, outputs, commands, queries, events, and expected responses to ensure a consistent consumer experience.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 9,
              "outcomes": [
                "Defined interaction model for the selected capability",
                "Inputs, outputs, commands, queries, events, and responses clarified",
                "Validation rules and interaction expectations agreed"
              ],
              "steps": [
                "Map interactions to user, consumer, or system tasks",
                "Define access points, operations, commands, queries, or events for each interaction",
                "Document inputs and outputs for each interaction.",
                "Specify validation rules and constraints",
                "Create interaction models for CRUD, query-driven, command-driven, and event-driven interactions"
              ],
              "canvasId": "interactionCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "contract-first-design",
              "slug": "resources/contract-first-design",
              "title": "Contract First Design",
              "description": "A guideline advocating for API-first approaches using formal contracts (e.g., OpenAPI) to align stakeholders before development.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 146,
              "outcomes": [
                "Shared understanding of the purpose and use of Contract First Design",
                "A consistent approach to applying Contract First Design",
                "Improved application of the related practices"
              ],
              "steps": [
                "Apply contract-first or design-first approaches to ensure API interface contracts are validated before implementation.",
                "Define API interface contracts that outline the expectations, responsibilities, and usage guidelines for each API.",
                "Use standardized formats (e.g., OpenAPI, AsyncAPI) to create machine-readable API interface contracts that are easy to share and validate."
              ],
              "canvasId": null,
              "sourcePath": "src/snippets/api-contract-example.yaml",
              "sourceUrl": null,
              "contentMarkdown": "openapi: 3.0.3\r\ninfo:\r\n  title: Sample Catalog API\r\n  version: 1.0.0\r\n  description: |\r\n    Starter example for a read-only APIOps Cycles API.\r\n    This example keeps the contract audit-friendly and easy to extend.\r\nservers:\r\n  - url: /v1\r\n    description: Versioned API base path\r\ntags:\r\n  - name: catalog\r\n    description: Browse and search catalog items\r\npaths:\r\n  /items:\r\n    get:\r\n      tags: [catalog]\r\n      summary: List catalog items\r\n      description: Returns a paginated list of public catalog items.\r\n      operationId: listItems\r\n      parameters:\r\n        - $ref: \"#/components/parameters/searchTerm\"\r\n        - $ref: \"#/components/parameters/categoryId\"\r\n        - $ref: \"#/components/parameters/page\"\r\n        - $ref: \"#/components/parameters/pageSize\"\r\n      responses:\r\n        \"200\":\r\n          description: Item list\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemListResponse\"\r\n              examples:\r\n                default:\r\n                  value:\r\n                    data:\r\n                      - itemId: item-123\r\n                        slug: blue-widget\r\n                        name: Blue Widget\r\n                        status: published\r\n                    page:\r\n                      number: 1\r\n                      size: 20\r\n                      totalItems: 1\r\n        \"400\":\r\n          $ref: \"#/components/responses/BadRequest\"\r\n        \"429\":\r\n          $ref: \"#/components/responses/TooManyRequests\"\r\n  /items/{itemId}:\r\n    get:\r\n      tags: [catalog]\r\n      summary: Get item by id\r\n      description: Returns a single public catalog item by opaque identifier.\r\n      operationId: getItemById\r\n      parameters:\r\n        - $ref: \"#/components/parameters/itemId\"\r\n      responses:\r\n        \"200\":\r\n          description: Item details\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemDetail\"\r\n        \"400\":\r\n          $ref: \"#/components/responses/BadRequest\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\n  /items/by-slug/{slug}:\r\n    get:\r\n      tags: [catalog]\r\n      summary: Get item by slug\r\n      description: Returns a single item by public slug.\r\n      operationId: getItemBySlug\r\n      parameters:\r\n        - $ref: \"#/components/parameters/slug\"\r\n      responses:\r\n        \"200\":\r\n          description: Item details\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemDetail\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\n  /categories/{categoryId}/items:\r\n    get:\r\n      tags: [catalog]\r\n      summary: List items in category\r\n      description: Returns public items in a category.\r\n      operationId: listItemsByCategory\r\n      parameters:\r\n        - $ref: \"#/components/parameters/categoryId\"\r\n      responses:\r\n        \"200\":\r\n          description: Category item list\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemListResponse\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\ncomponents:\r\n  parameters:\r\n    itemId:\r\n      name: itemId\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9][a-z0-9-]{1,63}$\"\r\n      example: item-123\r\n    slug:\r\n      name: slug\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9]+(?:-[a-z0-9]+)*$\"\r\n      example: blue-widget\r\n    categoryId:\r\n      name: categoryId\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9][a-z0-9-]{1,63}$\"\r\n      example: home-goods\r\n    searchTerm:\r\n      name: searchTerm\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: string\r\n        minLength: 1\r\n      example: widget\r\n    page:\r\n      name: page\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: integer\r\n        minimum: 1\r\n        default: 1\r\n    pageSize:\r\n      name: pageSize\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: integer\r\n        minimum: 1\r\n        maximum: 100\r\n        default: 20\r\n  responses:\r\n    BadRequest:\r\n      description: Validation failed\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n          examples:\r\n            default:\r\n              value:\r\n                code: BAD_REQUEST\r\n                message: Invalid request\r\n    NotFound:\r\n      description: Resource not found\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n    TooManyRequests:\r\n      description: Rate limit exceeded\r\n      headers:\r\n        Retry-After:\r\n          schema:\r\n            type: integer\r\n          description: Seconds until the next allowed request.\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n  schemas:\r\n    ItemListResponse:\r\n      type: object\r\n      required: [data, page]\r\n      properties:\r\n        data:\r\n          type: array\r\n          items:\r\n            $ref: \"#/components/schemas/ItemSummary\"\r\n        page:\r\n          $ref: \"#/components/schemas/Page\"\r\n    ItemSummary:\r\n      type: object\r\n      required: [itemId, slug, name, status]\r\n      properties:\r\n        itemId:\r\n          type: string\r\n        slug:\r\n          type: string\r\n        name:\r\n          type: string\r\n        status:\r\n          type: string\r\n          enum: [published, hidden]\r\n    ItemDetail:\r\n      allOf:\r\n        - $ref: \"#/components/schemas/ItemSummary\"\r\n        - type: object\r\n          properties:\r\n            description:\r\n              type: string\r\n            categories:\r\n              type: array\r\n              items:\r\n                type: string\r\n            variants:\r\n              type: array\r\n              items:\r\n                $ref: \"#/components/schemas/Variant\"\r\n    Variant:\r\n      type: object\r\n      required: [variantId, sku, price, inventory]\r\n      properties:\r\n        variantId:\r\n          type: string\r\n        sku:\r\n          type: string\r\n        price:\r\n          $ref: \"#/components/schemas/Price\"\r\n        inventory:\r\n          $ref: \"#/components/schemas/Inventory\"\r\n    Price:\r\n      type: object\r\n      required: [amount, currency]\r\n      properties:\r\n        amount:\r\n          type: number\r\n          format: decimal\r\n        currency:\r\n          type: string\r\n          example: EUR\r\n    Inventory:\r\n      type: object\r\n      required: [available]\r\n      properties:\r\n        available:\r\n          type: integer\r\n          minimum: 0\r\n        reserved:\r\n          type: integer\r\n          minimum: 0\r\n        source:\r\n          type: string\r\n    Page:\r\n      type: object\r\n      required: [number, size, totalItems]\r\n      properties:\r\n        number:\r\n          type: integer\r\n        size:\r\n          type: integer\r\n        totalItems:\r\n          type: integer\r\n    ErrorResponse:\r\n      type: object\r\n      required: [code, message]\r\n      properties:\r\n        code:\r\n          type: string\r\n        message:\r\n          type: string\r\n",
              "draft": true
            },
            {
              "id": "customerJourneyCanvas",
              "slug": "resources/customer-journey-canvas",
              "title": "Customer Journey Canvas",
              "description": "Map customer, partner, or consumer journeys to identify needs, pain points, gains, inputs, outputs, and experience expectations.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 1,
              "outcomes": [
                "Shared understanding of the customer, partner, or consumer journey",
                "Needs, pain points, gains, inputs, and outputs documented",
                "Journey evidence available for capability, requirements, and architecture decisions"
              ],
              "steps": [
                "Define customer persona",
                "Identify triggers for the journey",
                "Describe the journey's end",
                "Map journey steps with inputs/outputs",
                "Identify customer pains",
                "Summarize customer gains",
                "Define necessary inputs and resulting outputs",
                "Define interactions and processing expectations for each step"
              ],
              "canvasId": "customerJourneyCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capabilityValuePropositionCanvas",
              "slug": "resources/capability-value-proposition-canvas",
              "title": "Capability Value Proposition Canvas",
              "description": "A technology-agnostic canvas for mapping consumer tasks, gains, pains, and candidate reusable capabilities before selecting an implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 2.1,
              "outcomes": [
                "Clear reusable capability value proposition",
                "Consumer tasks, gains, and pains captured without assuming a technology",
                "Candidate reusable capabilities identified for architecture evaluation"
              ],
              "steps": [
                "List the consumer tasks and outcomes the capability should support.",
                "Identify gain-enabling capability features.",
                "Identify pain-relieving capability features.",
                "Group the features into candidate reusable capabilities."
              ],
              "canvasId": "capabilityValuePropositionCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capabilityBusinessModelCanvas",
              "slug": "resources/capability-business-model-canvas",
              "title": "Capability Business Model Canvas",
              "description": "A business model canvas for reusable capabilities, covering value, consumers, ownership, engagement, costs, and benefits without assuming an implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 3.1,
              "outcomes": [
                "Viable reusable capability operating model",
                "Ownership, consumers, channels, partners, and support needs clarified",
                "Costs and benefits visible before architecture commitment"
              ],
              "steps": [
                "Summarize the capability value proposition.",
                "Identify consumer segments and engagement channels.",
                "Define key activities, resources, and partners.",
                "Capture costs and benefits.",
                "Clarify ownership, funding, support, and lifecycle expectations.",
                "Validate the model with consumers, producers, and governance stakeholders."
              ],
              "canvasId": "capabilityBusinessModelCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "consumerExperienceRequirementsCanvas",
              "slug": "resources/consumer-experience-requirements-canvas",
              "title": "Consumer Experience Requirements Canvas",
              "description": "A requirements canvas for consumer experience and non-functional needs that should guide the later architecture and implementation-style decision.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 3.2,
              "outcomes": [
                "Technology-agnostic consumer and service requirements",
                "Experience and non-functional needs captured before design starts",
                "Architecture implications documented for implementation-style selection"
              ],
              "steps": [
                "Capture consumer goals and usage context.",
                "Document availability, timeliness, volume, performance, data quality, and consistency expectations.",
                "Document security, privacy, onboarding, change, observability, support, and recovery expectations.",
                "Summarize what the requirements imply for possible implementation styles."
              ],
              "canvasId": "consumerExperienceRequirementsCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            }
          ],
          "promptIds": [
            "api-product-owner:facilitate-station",
            "api-product-owner:use-resources",
            "api-product-owner:next-actions"
          ]
        },
        {
          "id": "automation-engineer",
          "stakeholderId": "automation-engineer",
          "title": "Automation Engineer",
          "summary": "Implements, tests, integrates, and maintains automation solutions and supporting workflows.",
          "stakeholder": {
            "id": "automation-engineer",
            "sourceKey": "automation-engineer",
            "sourceStakeholderId": "automation-engineer",
            "title": "Automation Engineer",
            "description": "Implements, tests, integrates, and maintains automation solutions and supporting workflows.",
            "involvement": ""
          },
          "cycles": [
            {
              "id": "automation-cycle",
              "title": "Automation Cycle",
              "description": "A cycle for identifying, designing, delivering, enabling, and improving automation opportunities."
            }
          ],
          "stations": [
            {
              "id": "api-product-strategy",
              "title": "Strategy",
              "description": "Frame the business need as a reusable capability before choosing the implementation style."
            },
            {
              "id": "api-platform-architecture",
              "title": "Architecture & Platform Decisions",
              "description": "Use requirements and constraints to decide the right architecture pattern and enabling platform capabilities."
            },
            {
              "id": "api-design",
              "title": "Solution & Interface Design",
              "description": "Design the interface contract and interaction model after the architecture choice is justified."
            },
            {
              "id": "api-delivery",
              "title": "Delivery & Operations",
              "description": "Deliver the selected implementation style with appropriate engineering, testing, security, automation, and operational practices."
            },
            {
              "id": "api-audit",
              "title": "Quality & Readiness Assurance",
              "description": "Audit the capability interface contract, controls, support model, observability, documentation, and lifecycle readiness before release."
            },
            {
              "id": "api-publishing",
              "title": "Publishing & Enablement",
              "description": "Publish reusable capability information so consumers can discover, request, onboard, use, and get support."
            },
            {
              "id": "monitoring-and-improving",
              "title": "Monitoring & Improvement",
              "description": "Monitor usage, reliability, data quality, consumer outcomes, operational cost, and reuse opportunities after release."
            }
          ],
          "canvases": [
            {
              "id": "customerJourneyCanvas",
              "title": "Customer Journey Canvas"
            },
            {
              "id": "domainCanvas",
              "title": "Domain Canvas"
            },
            {
              "id": "capabilityValuePropositionCanvas",
              "title": "Capability Value Proposition Canvas"
            },
            {
              "id": "businessImpactCanvas",
              "title": "Business Impact Canvas"
            },
            {
              "id": "locationsCanvas",
              "title": "Locations Canvas"
            },
            {
              "id": "capacityCanvas",
              "title": "Capacity Canvas"
            },
            {
              "id": "interactionCanvas",
              "title": "Interaction Canvas"
            }
          ],
          "decisions": [
            "Map the customer or partner journey that creates the capability need and reveals tasks, pains, gains, inputs, outputs, and decision points.",
            "Define the core entities, attributes, relationships, ownership, and business rules that the capability must respect.",
            "Use the Capability Value Proposition Canvas to capture consumer tasks, gains, pains, and reusable capability features without naming the delivery technology too early.",
            "Use the Capability Business Model Canvas to clarify ownership, partners, channels, costs, benefits, support, and lifecycle expectations for the reusable capability.",
            "Use shared journey, domain, value proposition, and business model canvases to gather technology-agnostic requirements and decide whether the capability should be reusable.",
            "Integration and API work often jumps too quickly to a technical pattern. This station keeps the team focused on the business journey, domain meaning, value, reuse potential, ownership, and viability before selecting APIs, events, files, streams, data products, or direct integration."
          ],
          "outputs": [
            "A technology-agnostic capability opportunity statement",
            "Shared understanding of consumers, producers, domain concepts, and reuse potential",
            "A capability value proposition and business model before architecture selection",
            "design-artifact",
            "documentation",
            "research",
            "roadmap",
            "A justified architecture choice"
          ],
          "recommendedResources": [
            {
              "id": "customerJourneyCanvas",
              "slug": "resources/customer-journey-canvas",
              "title": "Customer Journey Canvas",
              "description": "Map customer, partner, or consumer journeys to identify needs, pain points, gains, inputs, outputs, and experience expectations.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 1,
              "outcomes": [
                "Shared understanding of the customer, partner, or consumer journey",
                "Needs, pain points, gains, inputs, and outputs documented",
                "Journey evidence available for capability, requirements, and architecture decisions"
              ],
              "steps": [
                "Define customer persona",
                "Identify triggers for the journey",
                "Describe the journey's end",
                "Map journey steps with inputs/outputs",
                "Identify customer pains",
                "Summarize customer gains",
                "Define necessary inputs and resulting outputs",
                "Define interactions and processing expectations for each step"
              ],
              "canvasId": "customerJourneyCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "domainCanvas",
              "slug": "resources/domain-canvas",
              "title": "Domain Canvas",
              "description": "A modeling tool to define and communicate the key entities and relationships in your domain, ensuring semantic consistency across capabilities, integrations, APIs, data products, and services.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 152,
              "outcomes": [
                "Shared domain model and terminology",
                "Core entities, relationships, rules, and ownership clarified",
                "Semantic consistency across capabilities, integrations, APIs, data products, and services"
              ],
              "steps": [
                "Define core entities, their attributes, and relationships to create a shared conceptual understanding across capabilities, integrations, APIs, data products, and services."
              ],
              "canvasId": "domainCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capabilityValuePropositionCanvas",
              "slug": "resources/capability-value-proposition-canvas",
              "title": "Capability Value Proposition Canvas",
              "description": "A technology-agnostic canvas for mapping consumer tasks, gains, pains, and candidate reusable capabilities before selecting an implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 2.1,
              "outcomes": [
                "Clear reusable capability value proposition",
                "Consumer tasks, gains, and pains captured without assuming a technology",
                "Candidate reusable capabilities identified for architecture evaluation"
              ],
              "steps": [
                "List the consumer tasks and outcomes the capability should support.",
                "Identify gain-enabling capability features.",
                "Identify pain-relieving capability features.",
                "Group the features into candidate reusable capabilities."
              ],
              "canvasId": "capabilityValuePropositionCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "businessImpactCanvas",
              "slug": "resources/business-impact-canvas",
              "title": "Business Impact Canvas",
              "description": "Identify business, availability, security, data, compliance, and operational risks that should shape architecture and platform decisions.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 4,
              "outcomes": [
                "Documented business and operational impact assessment",
                "Prioritized risks and mitigation actions",
                "Evidence for architecture and platform decisions"
              ],
              "steps": [
                "Availability Risks: Identify risks and impacts.",
                "Ways to Mitigate Availability Risks: Define mitigation measures.",
                "Security Risks: Document security-related risks.",
                "Ways to Mitigate Security Risks: Propose strategies to mitigate security risks.",
                "Data Risks: Identify risks to data accuracy or availability.",
                "Ways to Mitigate Data Risks: Plan strategies to address data risks."
              ],
              "canvasId": "businessImpactCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "locationsCanvas",
              "slug": "resources/location-canvas",
              "title": "Location Canvas",
              "description": "Map consumer, producer, system, data, network, regulatory, and trust-boundary locations to ensure compliance and performance across regions.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 6,
              "outcomes": [
                "Documented location, residency, network, and regulatory requirements",
                "Regional performance and accessibility constraints identified",
                "Data residency, trust boundaries, and applicable regulations clarified"
              ],
              "steps": [
                "Map locations of producers, source systems, platforms, and consumers.",
                "Document where consumers are located.",
                "Identify applicable regulations.",
                "Document where data must reside.",
                "Ensure the capability is accessible in all intended network regions.",
                "Validate network performance across regions."
              ],
              "canvasId": "locationsCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capacityCanvas",
              "slug": "resources/capacity-canvas",
              "title": "Capacity Canvas",
              "description": "Plan capacity for current and future demand, including volumes, peaks, latency, availability, scaling, caching, and rate limits for the selected capability and implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 7,
              "outcomes": [
                "Capacity requirements aligned with expected business demand",
                "Peak-load, availability, and growth assumptions documented",
                "Scaling, caching, and rate-limiting decisions defined"
              ],
              "steps": [
                "Document current business volumes",
                "Forecast future consumption trends",
                "Plan for peak load and availability requirements",
                "Define caching and rate-limiting strategies",
                "Propose scaling strategies"
              ],
              "canvasId": "capacityCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "automation-operational-ownership-guide",
              "slug": "resources/automation-operational-ownership-guide",
              "title": "Automation Operational Ownership Guide",
              "description": "Guidance for defining ownership, runbooks, supervision, support, monitoring, change control, and continuous improvement responsibilities for automations.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 185,
              "outcomes": [
                "Clear automation operating model",
                "Ownership, support, and escalation responsibilities assigned",
                "Monitoring and change practices ready for live operation"
              ],
              "steps": [
                "Define business, technical, and operational owners for the automation.",
                "Document runbooks, support paths, monitoring signals, service expectations, and escalation rules.",
                "Set change control and review practices for workflow, platform, and rule updates."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "interactionCanvas",
              "slug": "resources/interaction-canvas",
              "title": "Interaction Canvas",
              "description": "Define interactions, workflows, inputs, outputs, commands, queries, events, and expected responses to ensure a consistent consumer experience.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 9,
              "outcomes": [
                "Defined interaction model for the selected capability",
                "Inputs, outputs, commands, queries, events, and responses clarified",
                "Validation rules and interaction expectations agreed"
              ],
              "steps": [
                "Map interactions to user, consumer, or system tasks",
                "Define access points, operations, commands, queries, or events for each interaction",
                "Document inputs and outputs for each interaction.",
                "Specify validation rules and constraints",
                "Create interaction models for CRUD, query-driven, command-driven, and event-driven interactions"
              ],
              "canvasId": "interactionCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "process-workflow-design-guide",
              "slug": "resources/process-workflow-design-guide",
              "title": "Process Workflow Design Guide",
              "description": "Guidance for modeling the process steps, roles, handoffs, decision points, states, inputs, outputs, and exceptions that shape an automation workflow.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 181,
              "outcomes": [
                "Clear automation workflow design",
                "Process steps and handoffs documented before implementation",
                "Workflow states, inputs, outputs, and exception paths understood"
              ],
              "steps": [
                "Map the current and target process flow, including human and system responsibilities.",
                "Identify workflow triggers, states, decisions, data inputs, outputs, and completion criteria.",
                "Document handoffs between users, systems, operations, and support roles.",
                "Confirm which steps should be automated and which require human judgment."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "decision-business-rules-guide",
              "slug": "resources/decision-business-rules-guide",
              "title": "Decision And Business Rules Guide",
              "description": "Guidance for capturing rules, thresholds, decisions, approvals, eligibility checks, and rule ownership for automation design.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 182,
              "outcomes": [
                "Explicit decisions and business rules",
                "Rules and thresholds documented with owners",
                "Automation decisions traceable to policy, process, or business intent"
              ],
              "steps": [
                "List decisions the automation must make or support.",
                "Document rule conditions, thresholds, exceptions, approvals, and escalation points.",
                "Identify rule owners and change governance for each decision area."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            }
          ],
          "promptIds": [
            "automation-engineer:facilitate-station",
            "automation-engineer:use-resources",
            "automation-engineer:next-actions"
          ]
        },
        {
          "id": "automation-owner",
          "stakeholderId": "automation-owner",
          "title": "Automation Owner",
          "summary": "Owns automation goals, business value, priorities, controls, and lifecycle outcomes.",
          "stakeholder": {
            "id": "automation-owner",
            "sourceKey": "automation-owner",
            "sourceStakeholderId": "automation-owner",
            "title": "Automation Owner",
            "description": "Owns automation goals, business value, priorities, controls, and lifecycle outcomes.",
            "involvement": ""
          },
          "cycles": [
            {
              "id": "automation-cycle",
              "title": "Automation Cycle",
              "description": "A cycle for identifying, designing, delivering, enabling, and improving automation opportunities."
            }
          ],
          "stations": [
            {
              "id": "api-product-strategy",
              "title": "Strategy",
              "description": "Frame the business need as a reusable capability before choosing the implementation style."
            },
            {
              "id": "api-consumer-experience",
              "title": "Consumer Requirements & Onboarding",
              "description": "Capture consumer onboarding, standards, non-functional requirements, service expectations, constraints, security needs, allowed protocols, data freshness, SLAs, observability, recovery, adoption requirements, and producer responsibilities."
            },
            {
              "id": "api-platform-architecture",
              "title": "Architecture & Platform Decisions",
              "description": "Use requirements and constraints to decide the right architecture pattern and enabling platform capabilities."
            },
            {
              "id": "api-design",
              "title": "Solution & Interface Design",
              "description": "Design the interface contract and interaction model after the architecture choice is justified."
            },
            {
              "id": "api-delivery",
              "title": "Delivery & Operations",
              "description": "Deliver the selected implementation style with appropriate engineering, testing, security, automation, and operational practices."
            },
            {
              "id": "api-audit",
              "title": "Quality & Readiness Assurance",
              "description": "Audit the capability interface contract, controls, support model, observability, documentation, and lifecycle readiness before release."
            },
            {
              "id": "api-publishing",
              "title": "Publishing & Enablement",
              "description": "Publish reusable capability information so consumers can discover, request, onboard, use, and get support."
            },
            {
              "id": "monitoring-and-improving",
              "title": "Monitoring & Improvement",
              "description": "Monitor usage, reliability, data quality, consumer outcomes, operational cost, and reuse opportunities after release."
            }
          ],
          "canvases": [
            {
              "id": "customerJourneyCanvas",
              "title": "Customer Journey Canvas"
            },
            {
              "id": "domainCanvas",
              "title": "Domain Canvas"
            },
            {
              "id": "capabilityValuePropositionCanvas",
              "title": "Capability Value Proposition Canvas"
            },
            {
              "id": "consumerExperienceRequirementsCanvas",
              "title": "Consumer Experience Requirements Canvas"
            },
            {
              "id": "businessImpactCanvas",
              "title": "Business Impact Canvas"
            },
            {
              "id": "locationsCanvas",
              "title": "Locations Canvas"
            },
            {
              "id": "capacityCanvas",
              "title": "Capacity Canvas"
            },
            {
              "id": "interactionCanvas",
              "title": "Interaction Canvas"
            }
          ],
          "decisions": [
            "Map the customer or partner journey that creates the capability need and reveals tasks, pains, gains, inputs, outputs, and decision points.",
            "Define the core entities, attributes, relationships, ownership, and business rules that the capability must respect.",
            "Use the Capability Value Proposition Canvas to capture consumer tasks, gains, pains, and reusable capability features without naming the delivery technology too early.",
            "Use the Capability Business Model Canvas to clarify ownership, partners, channels, costs, benefits, support, and lifecycle expectations for the reusable capability.",
            "Use shared journey, domain, value proposition, and business model canvases to gather technology-agnostic requirements and decide whether the capability should be reusable.",
            "Integration and API work often jumps too quickly to a technical pattern. This station keeps the team focused on the business journey, domain meaning, value, reuse potential, ownership, and viability before selecting APIs, events, files, streams, data products, or direct integration."
          ],
          "outputs": [
            "A technology-agnostic capability opportunity statement",
            "Shared understanding of consumers, producers, domain concepts, and reuse potential",
            "A capability value proposition and business model before architecture selection",
            "design-artifact",
            "documentation",
            "research",
            "roadmap",
            "Documented consumer requirements and onboarding expectations"
          ],
          "recommendedResources": [
            {
              "id": "customerJourneyCanvas",
              "slug": "resources/customer-journey-canvas",
              "title": "Customer Journey Canvas",
              "description": "Map customer, partner, or consumer journeys to identify needs, pain points, gains, inputs, outputs, and experience expectations.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 1,
              "outcomes": [
                "Shared understanding of the customer, partner, or consumer journey",
                "Needs, pain points, gains, inputs, and outputs documented",
                "Journey evidence available for capability, requirements, and architecture decisions"
              ],
              "steps": [
                "Define customer persona",
                "Identify triggers for the journey",
                "Describe the journey's end",
                "Map journey steps with inputs/outputs",
                "Identify customer pains",
                "Summarize customer gains",
                "Define necessary inputs and resulting outputs",
                "Define interactions and processing expectations for each step"
              ],
              "canvasId": "customerJourneyCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "domainCanvas",
              "slug": "resources/domain-canvas",
              "title": "Domain Canvas",
              "description": "A modeling tool to define and communicate the key entities and relationships in your domain, ensuring semantic consistency across capabilities, integrations, APIs, data products, and services.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 152,
              "outcomes": [
                "Shared domain model and terminology",
                "Core entities, relationships, rules, and ownership clarified",
                "Semantic consistency across capabilities, integrations, APIs, data products, and services"
              ],
              "steps": [
                "Define core entities, their attributes, and relationships to create a shared conceptual understanding across capabilities, integrations, APIs, data products, and services."
              ],
              "canvasId": "domainCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capabilityValuePropositionCanvas",
              "slug": "resources/capability-value-proposition-canvas",
              "title": "Capability Value Proposition Canvas",
              "description": "A technology-agnostic canvas for mapping consumer tasks, gains, pains, and candidate reusable capabilities before selecting an implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 2.1,
              "outcomes": [
                "Clear reusable capability value proposition",
                "Consumer tasks, gains, and pains captured without assuming a technology",
                "Candidate reusable capabilities identified for architecture evaluation"
              ],
              "steps": [
                "List the consumer tasks and outcomes the capability should support.",
                "Identify gain-enabling capability features.",
                "Identify pain-relieving capability features.",
                "Group the features into candidate reusable capabilities."
              ],
              "canvasId": "capabilityValuePropositionCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "consumerExperienceRequirementsCanvas",
              "slug": "resources/consumer-experience-requirements-canvas",
              "title": "Consumer Experience Requirements Canvas",
              "description": "A requirements canvas for consumer experience and non-functional needs that should guide the later architecture and implementation-style decision.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 3.2,
              "outcomes": [
                "Technology-agnostic consumer and service requirements",
                "Experience and non-functional needs captured before design starts",
                "Architecture implications documented for implementation-style selection"
              ],
              "steps": [
                "Capture consumer goals and usage context.",
                "Document availability, timeliness, volume, performance, data quality, and consistency expectations.",
                "Document security, privacy, onboarding, change, observability, support, and recovery expectations.",
                "Summarize what the requirements imply for possible implementation styles."
              ],
              "canvasId": "consumerExperienceRequirementsCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "businessImpactCanvas",
              "slug": "resources/business-impact-canvas",
              "title": "Business Impact Canvas",
              "description": "Identify business, availability, security, data, compliance, and operational risks that should shape architecture and platform decisions.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 4,
              "outcomes": [
                "Documented business and operational impact assessment",
                "Prioritized risks and mitigation actions",
                "Evidence for architecture and platform decisions"
              ],
              "steps": [
                "Availability Risks: Identify risks and impacts.",
                "Ways to Mitigate Availability Risks: Define mitigation measures.",
                "Security Risks: Document security-related risks.",
                "Ways to Mitigate Security Risks: Propose strategies to mitigate security risks.",
                "Data Risks: Identify risks to data accuracy or availability.",
                "Ways to Mitigate Data Risks: Plan strategies to address data risks."
              ],
              "canvasId": "businessImpactCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "locationsCanvas",
              "slug": "resources/location-canvas",
              "title": "Location Canvas",
              "description": "Map consumer, producer, system, data, network, regulatory, and trust-boundary locations to ensure compliance and performance across regions.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 6,
              "outcomes": [
                "Documented location, residency, network, and regulatory requirements",
                "Regional performance and accessibility constraints identified",
                "Data residency, trust boundaries, and applicable regulations clarified"
              ],
              "steps": [
                "Map locations of producers, source systems, platforms, and consumers.",
                "Document where consumers are located.",
                "Identify applicable regulations.",
                "Document where data must reside.",
                "Ensure the capability is accessible in all intended network regions.",
                "Validate network performance across regions."
              ],
              "canvasId": "locationsCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capacityCanvas",
              "slug": "resources/capacity-canvas",
              "title": "Capacity Canvas",
              "description": "Plan capacity for current and future demand, including volumes, peaks, latency, availability, scaling, caching, and rate limits for the selected capability and implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 7,
              "outcomes": [
                "Capacity requirements aligned with expected business demand",
                "Peak-load, availability, and growth assumptions documented",
                "Scaling, caching, and rate-limiting decisions defined"
              ],
              "steps": [
                "Document current business volumes",
                "Forecast future consumption trends",
                "Plan for peak load and availability requirements",
                "Define caching and rate-limiting strategies",
                "Propose scaling strategies"
              ],
              "canvasId": "capacityCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "automation-operational-ownership-guide",
              "slug": "resources/automation-operational-ownership-guide",
              "title": "Automation Operational Ownership Guide",
              "description": "Guidance for defining ownership, runbooks, supervision, support, monitoring, change control, and continuous improvement responsibilities for automations.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 185,
              "outcomes": [
                "Clear automation operating model",
                "Ownership, support, and escalation responsibilities assigned",
                "Monitoring and change practices ready for live operation"
              ],
              "steps": [
                "Define business, technical, and operational owners for the automation.",
                "Document runbooks, support paths, monitoring signals, service expectations, and escalation rules.",
                "Set change control and review practices for workflow, platform, and rule updates."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "interactionCanvas",
              "slug": "resources/interaction-canvas",
              "title": "Interaction Canvas",
              "description": "Define interactions, workflows, inputs, outputs, commands, queries, events, and expected responses to ensure a consistent consumer experience.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 9,
              "outcomes": [
                "Defined interaction model for the selected capability",
                "Inputs, outputs, commands, queries, events, and responses clarified",
                "Validation rules and interaction expectations agreed"
              ],
              "steps": [
                "Map interactions to user, consumer, or system tasks",
                "Define access points, operations, commands, queries, or events for each interaction",
                "Document inputs and outputs for each interaction.",
                "Specify validation rules and constraints",
                "Create interaction models for CRUD, query-driven, command-driven, and event-driven interactions"
              ],
              "canvasId": "interactionCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "process-workflow-design-guide",
              "slug": "resources/process-workflow-design-guide",
              "title": "Process Workflow Design Guide",
              "description": "Guidance for modeling the process steps, roles, handoffs, decision points, states, inputs, outputs, and exceptions that shape an automation workflow.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 181,
              "outcomes": [
                "Clear automation workflow design",
                "Process steps and handoffs documented before implementation",
                "Workflow states, inputs, outputs, and exception paths understood"
              ],
              "steps": [
                "Map the current and target process flow, including human and system responsibilities.",
                "Identify workflow triggers, states, decisions, data inputs, outputs, and completion criteria.",
                "Document handoffs between users, systems, operations, and support roles.",
                "Confirm which steps should be automated and which require human judgment."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            }
          ],
          "promptIds": [
            "automation-owner:facilitate-station",
            "automation-owner:use-resources",
            "automation-owner:next-actions"
          ]
        },
        {
          "id": "business-owner",
          "stakeholderId": "business-owner",
          "title": "Business Owner",
          "summary": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
          "stakeholder": {
            "id": "business-owner",
            "sourceKey": "business-owner",
            "sourceStakeholderId": "business-owner",
            "title": "Business Owner",
            "description": "Represents business goals, funding, and expected outcomes for the capability, API, or automation initiative.",
            "involvement": ""
          },
          "cycles": [
            {
              "id": "capability-productization-cycle",
              "title": "Capability Productization Cycle",
              "description": "A cycle for turning business capabilities into reusable digital capabilities before selecting the implementation style."
            },
            {
              "id": "api-productization-cycle",
              "title": "API Productization Cycle",
              "description": "The API-focused APIOps Cycles journey for productizing, designing, delivering, publishing, and improving APIs."
            },
            {
              "id": "integration-productization-cycle",
              "title": "Integration Productization Cycle",
              "description": "A cycle for productizing reusable integration capabilities before selecting the implementation style."
            },
            {
              "id": "automation-cycle",
              "title": "Automation Cycle",
              "description": "A cycle for identifying, designing, delivering, enabling, and improving automation opportunities."
            }
          ],
          "stations": [
            {
              "id": "api-product-strategy",
              "title": "Strategy",
              "description": "Frame the business need as a reusable capability before choosing the implementation style."
            },
            {
              "id": "api-consumer-experience",
              "title": "Consumer Requirements & Onboarding",
              "description": "Capture consumer onboarding, standards, non-functional requirements, service expectations, constraints, security needs, allowed protocols, data freshness, SLAs, observability, recovery, adoption requirements, and producer responsibilities."
            },
            {
              "id": "api-platform-architecture",
              "title": "Architecture & Platform Decisions",
              "description": "Use requirements and constraints to decide the right architecture pattern and enabling platform capabilities."
            },
            {
              "id": "api-publishing",
              "title": "Publishing & Enablement",
              "description": "Publish reusable capability information so consumers can discover, request, onboard, use, and get support."
            },
            {
              "id": "monitoring-and-improving",
              "title": "Monitoring & Improvement",
              "description": "Monitor usage, reliability, data quality, consumer outcomes, operational cost, and reuse opportunities after release."
            },
            {
              "id": "api-design",
              "title": "Solution & Interface Design",
              "description": "Design the interface contract and interaction model after the architecture choice is justified."
            },
            {
              "id": "api-delivery",
              "title": "Delivery & Operations",
              "description": "Deliver the selected implementation style with appropriate engineering, testing, security, automation, and operational practices."
            },
            {
              "id": "api-audit",
              "title": "Quality & Readiness Assurance",
              "description": "Audit the capability interface contract, controls, support model, observability, documentation, and lifecycle readiness before release."
            }
          ],
          "canvases": [
            {
              "id": "customerJourneyCanvas",
              "title": "Customer Journey Canvas"
            },
            {
              "id": "domainCanvas",
              "title": "Domain Canvas"
            },
            {
              "id": "capabilityValuePropositionCanvas",
              "title": "Capability Value Proposition Canvas"
            },
            {
              "id": "capabilityBusinessModelCanvas",
              "title": "Capability Business Model Canvas"
            },
            {
              "id": "consumerExperienceRequirementsCanvas",
              "title": "Consumer Experience Requirements Canvas"
            },
            {
              "id": "businessImpactCanvas",
              "title": "Business Impact Canvas"
            },
            {
              "id": "locationsCanvas",
              "title": "Locations Canvas"
            },
            {
              "id": "capacityCanvas",
              "title": "Capacity Canvas"
            },
            {
              "id": "interactionCanvas",
              "title": "Interaction Canvas"
            },
            {
              "id": "apiValuePropositionCanvas",
              "title": "API Value Proposition Canvas"
            },
            {
              "id": "apiBusinessModelCanvas",
              "title": "API Business Model Canvas"
            },
            {
              "id": "restCanvas",
              "title": "REST Canvas"
            },
            {
              "id": "eventCanvas",
              "title": "Event Canvas"
            },
            {
              "id": "graphqlCanvas",
              "title": "GraphQL Canvas"
            }
          ],
          "decisions": [
            "Map the customer or partner journey that creates the capability need and reveals tasks, pains, gains, inputs, outputs, and decision points.",
            "Define the core entities, attributes, relationships, ownership, and business rules that the capability must respect.",
            "Use the Capability Value Proposition Canvas to capture consumer tasks, gains, pains, and reusable capability features without naming the delivery technology too early.",
            "Use the Capability Business Model Canvas to clarify ownership, partners, channels, costs, benefits, support, and lifecycle expectations for the reusable capability.",
            "Use shared journey, domain, value proposition, and business model canvases to gather technology-agnostic requirements and decide whether the capability should be reusable.",
            "Integration and API work often jumps too quickly to a technical pattern. This station keeps the team focused on the business journey, domain meaning, value, reuse potential, ownership, and viability before selecting APIs, events, files, streams, data products, or direct integration."
          ],
          "outputs": [
            "A technology-agnostic capability opportunity statement",
            "Shared understanding of consumers, producers, domain concepts, and reuse potential",
            "A capability value proposition and business model before architecture selection",
            "design-artifact",
            "documentation",
            "research",
            "roadmap",
            "Documented consumer requirements and onboarding expectations"
          ],
          "recommendedResources": [
            {
              "id": "customerJourneyCanvas",
              "slug": "resources/customer-journey-canvas",
              "title": "Customer Journey Canvas",
              "description": "Map customer, partner, or consumer journeys to identify needs, pain points, gains, inputs, outputs, and experience expectations.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 1,
              "outcomes": [
                "Shared understanding of the customer, partner, or consumer journey",
                "Needs, pain points, gains, inputs, and outputs documented",
                "Journey evidence available for capability, requirements, and architecture decisions"
              ],
              "steps": [
                "Define customer persona",
                "Identify triggers for the journey",
                "Describe the journey's end",
                "Map journey steps with inputs/outputs",
                "Identify customer pains",
                "Summarize customer gains",
                "Define necessary inputs and resulting outputs",
                "Define interactions and processing expectations for each step"
              ],
              "canvasId": "customerJourneyCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "domainCanvas",
              "slug": "resources/domain-canvas",
              "title": "Domain Canvas",
              "description": "A modeling tool to define and communicate the key entities and relationships in your domain, ensuring semantic consistency across capabilities, integrations, APIs, data products, and services.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 152,
              "outcomes": [
                "Shared domain model and terminology",
                "Core entities, relationships, rules, and ownership clarified",
                "Semantic consistency across capabilities, integrations, APIs, data products, and services"
              ],
              "steps": [
                "Define core entities, their attributes, and relationships to create a shared conceptual understanding across capabilities, integrations, APIs, data products, and services."
              ],
              "canvasId": "domainCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capabilityValuePropositionCanvas",
              "slug": "resources/capability-value-proposition-canvas",
              "title": "Capability Value Proposition Canvas",
              "description": "A technology-agnostic canvas for mapping consumer tasks, gains, pains, and candidate reusable capabilities before selecting an implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 2.1,
              "outcomes": [
                "Clear reusable capability value proposition",
                "Consumer tasks, gains, and pains captured without assuming a technology",
                "Candidate reusable capabilities identified for architecture evaluation"
              ],
              "steps": [
                "List the consumer tasks and outcomes the capability should support.",
                "Identify gain-enabling capability features.",
                "Identify pain-relieving capability features.",
                "Group the features into candidate reusable capabilities."
              ],
              "canvasId": "capabilityValuePropositionCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capabilityBusinessModelCanvas",
              "slug": "resources/capability-business-model-canvas",
              "title": "Capability Business Model Canvas",
              "description": "A business model canvas for reusable capabilities, covering value, consumers, ownership, engagement, costs, and benefits without assuming an implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 3.1,
              "outcomes": [
                "Viable reusable capability operating model",
                "Ownership, consumers, channels, partners, and support needs clarified",
                "Costs and benefits visible before architecture commitment"
              ],
              "steps": [
                "Summarize the capability value proposition.",
                "Identify consumer segments and engagement channels.",
                "Define key activities, resources, and partners.",
                "Capture costs and benefits.",
                "Clarify ownership, funding, support, and lifecycle expectations.",
                "Validate the model with consumers, producers, and governance stakeholders."
              ],
              "canvasId": "capabilityBusinessModelCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "consumerExperienceRequirementsCanvas",
              "slug": "resources/consumer-experience-requirements-canvas",
              "title": "Consumer Experience Requirements Canvas",
              "description": "A requirements canvas for consumer experience and non-functional needs that should guide the later architecture and implementation-style decision.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 3.2,
              "outcomes": [
                "Technology-agnostic consumer and service requirements",
                "Experience and non-functional needs captured before design starts",
                "Architecture implications documented for implementation-style selection"
              ],
              "steps": [
                "Capture consumer goals and usage context.",
                "Document availability, timeliness, volume, performance, data quality, and consistency expectations.",
                "Document security, privacy, onboarding, change, observability, support, and recovery expectations.",
                "Summarize what the requirements imply for possible implementation styles."
              ],
              "canvasId": "consumerExperienceRequirementsCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "api-onboarding-best-practices",
              "slug": "resources/api-onboarding-best-practices",
              "title": "API Onboarding Best Practices",
              "description": "Best practices to streamline API consumer onboarding journeys with step-by-step registration, discovery, and first-call guidance.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 121,
              "outcomes": [
                "Shared understanding of the purpose and use of API Onboarding Best Practices",
                "A consistent approach to applying API Onboarding Best Practices",
                "Improved application of the related practices"
              ],
              "steps": [
                "Define the API consumer journey from discovery to troubleshooting, identifying key touchpoints and pain points.",
                "Develop onboarding processes and resources to help API consumers understand how to use APIs effectively.",
                "Document how consumers find and use the API, including onboarding processes and registration."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "businessImpactCanvas",
              "slug": "resources/business-impact-canvas",
              "title": "Business Impact Canvas",
              "description": "Identify business, availability, security, data, compliance, and operational risks that should shape architecture and platform decisions.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 4,
              "outcomes": [
                "Documented business and operational impact assessment",
                "Prioritized risks and mitigation actions",
                "Evidence for architecture and platform decisions"
              ],
              "steps": [
                "Availability Risks: Identify risks and impacts.",
                "Ways to Mitigate Availability Risks: Define mitigation measures.",
                "Security Risks: Document security-related risks.",
                "Ways to Mitigate Security Risks: Propose strategies to mitigate security risks.",
                "Data Risks: Identify risks to data accuracy or availability.",
                "Ways to Mitigate Data Risks: Plan strategies to address data risks."
              ],
              "canvasId": "businessImpactCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "locationsCanvas",
              "slug": "resources/location-canvas",
              "title": "Location Canvas",
              "description": "Map consumer, producer, system, data, network, regulatory, and trust-boundary locations to ensure compliance and performance across regions.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 6,
              "outcomes": [
                "Documented location, residency, network, and regulatory requirements",
                "Regional performance and accessibility constraints identified",
                "Data residency, trust boundaries, and applicable regulations clarified"
              ],
              "steps": [
                "Map locations of producers, source systems, platforms, and consumers.",
                "Document where consumers are located.",
                "Identify applicable regulations.",
                "Document where data must reside.",
                "Ensure the capability is accessible in all intended network regions.",
                "Validate network performance across regions."
              ],
              "canvasId": "locationsCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capacityCanvas",
              "slug": "resources/capacity-canvas",
              "title": "Capacity Canvas",
              "description": "Plan capacity for current and future demand, including volumes, peaks, latency, availability, scaling, caching, and rate limits for the selected capability and implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 7,
              "outcomes": [
                "Capacity requirements aligned with expected business demand",
                "Peak-load, availability, and growth assumptions documented",
                "Scaling, caching, and rate-limiting decisions defined"
              ],
              "steps": [
                "Document current business volumes",
                "Forecast future consumption trends",
                "Plan for peak load and availability requirements",
                "Define caching and rate-limiting strategies",
                "Propose scaling strategies"
              ],
              "canvasId": "capacityCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "service-agreement-template",
              "slug": "resources/service-agreement-template",
              "title": "Service Agreement Template",
              "description": "A customizable agreement format that defines expectations, SLAs, responsibilities, and access terms for API consumption.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 172,
              "outcomes": [
                "Shared understanding of the purpose and use of Service Agreement Template",
                "A consistent approach to applying Service Agreement Template",
                "Improved application of the related practices"
              ],
              "steps": [
                "Define service agreements that outline the expectations, service levels, and responsibilities for each API.",
                "Use standardized formats to create machine-readable service agreements that are easy to share and validate.",
                "Ensure service agreements are reviewed and approved by stakeholders to ensure alignment and clarity."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            }
          ],
          "promptIds": [
            "business-owner:facilitate-station",
            "business-owner:use-resources",
            "business-owner:next-actions"
          ]
        },
        {
          "id": "capability-owner",
          "stakeholderId": "capability-owner",
          "title": "Capability Owner",
          "summary": "Owns the capability vision, value, priorities, lifecycle, and reuse across consumers.",
          "stakeholder": {
            "id": "capability-owner",
            "sourceKey": "capability-owner",
            "sourceStakeholderId": "capability-owner",
            "title": "Capability Owner",
            "description": "Owns the capability vision, value, priorities, lifecycle, and reuse across consumers.",
            "involvement": ""
          },
          "cycles": [
            {
              "id": "capability-productization-cycle",
              "title": "Capability Productization Cycle",
              "description": "A cycle for turning business capabilities into reusable digital capabilities before selecting the implementation style."
            },
            {
              "id": "integration-productization-cycle",
              "title": "Integration Productization Cycle",
              "description": "A cycle for productizing reusable integration capabilities before selecting the implementation style."
            }
          ],
          "stations": [
            {
              "id": "api-product-strategy",
              "title": "Strategy",
              "description": "Frame the business need as a reusable capability before choosing the implementation style."
            },
            {
              "id": "api-consumer-experience",
              "title": "Consumer Requirements & Onboarding",
              "description": "Capture consumer onboarding, standards, non-functional requirements, service expectations, constraints, security needs, allowed protocols, data freshness, SLAs, observability, recovery, adoption requirements, and producer responsibilities."
            },
            {
              "id": "api-platform-architecture",
              "title": "Architecture & Platform Decisions",
              "description": "Use requirements and constraints to decide the right architecture pattern and enabling platform capabilities."
            },
            {
              "id": "api-design",
              "title": "Solution & Interface Design",
              "description": "Design the interface contract and interaction model after the architecture choice is justified."
            },
            {
              "id": "api-delivery",
              "title": "Delivery & Operations",
              "description": "Deliver the selected implementation style with appropriate engineering, testing, security, automation, and operational practices."
            },
            {
              "id": "api-audit",
              "title": "Quality & Readiness Assurance",
              "description": "Audit the capability interface contract, controls, support model, observability, documentation, and lifecycle readiness before release."
            },
            {
              "id": "api-publishing",
              "title": "Publishing & Enablement",
              "description": "Publish reusable capability information so consumers can discover, request, onboard, use, and get support."
            },
            {
              "id": "monitoring-and-improving",
              "title": "Monitoring & Improvement",
              "description": "Monitor usage, reliability, data quality, consumer outcomes, operational cost, and reuse opportunities after release."
            }
          ],
          "canvases": [
            {
              "id": "customerJourneyCanvas",
              "title": "Customer Journey Canvas"
            },
            {
              "id": "domainCanvas",
              "title": "Domain Canvas"
            },
            {
              "id": "capabilityValuePropositionCanvas",
              "title": "Capability Value Proposition Canvas"
            },
            {
              "id": "capabilityBusinessModelCanvas",
              "title": "Capability Business Model Canvas"
            },
            {
              "id": "consumerExperienceRequirementsCanvas",
              "title": "Consumer Experience Requirements Canvas"
            },
            {
              "id": "businessImpactCanvas",
              "title": "Business Impact Canvas"
            },
            {
              "id": "locationsCanvas",
              "title": "Locations Canvas"
            },
            {
              "id": "capacityCanvas",
              "title": "Capacity Canvas"
            },
            {
              "id": "interactionCanvas",
              "title": "Interaction Canvas"
            },
            {
              "id": "restCanvas",
              "title": "REST Canvas"
            },
            {
              "id": "eventCanvas",
              "title": "Event Canvas"
            },
            {
              "id": "graphqlCanvas",
              "title": "GraphQL Canvas"
            }
          ],
          "decisions": [
            "Map the customer or partner journey that creates the capability need and reveals tasks, pains, gains, inputs, outputs, and decision points.",
            "Define the core entities, attributes, relationships, ownership, and business rules that the capability must respect.",
            "Use the Capability Value Proposition Canvas to capture consumer tasks, gains, pains, and reusable capability features without naming the delivery technology too early.",
            "Use the Capability Business Model Canvas to clarify ownership, partners, channels, costs, benefits, support, and lifecycle expectations for the reusable capability.",
            "Use shared journey, domain, value proposition, and business model canvases to gather technology-agnostic requirements and decide whether the capability should be reusable.",
            "Integration and API work often jumps too quickly to a technical pattern. This station keeps the team focused on the business journey, domain meaning, value, reuse potential, ownership, and viability before selecting APIs, events, files, streams, data products, or direct integration."
          ],
          "outputs": [
            "A technology-agnostic capability opportunity statement",
            "Shared understanding of consumers, producers, domain concepts, and reuse potential",
            "A capability value proposition and business model before architecture selection",
            "design-artifact",
            "documentation",
            "research",
            "roadmap",
            "Documented consumer requirements and onboarding expectations"
          ],
          "recommendedResources": [
            {
              "id": "customerJourneyCanvas",
              "slug": "resources/customer-journey-canvas",
              "title": "Customer Journey Canvas",
              "description": "Map customer, partner, or consumer journeys to identify needs, pain points, gains, inputs, outputs, and experience expectations.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 1,
              "outcomes": [
                "Shared understanding of the customer, partner, or consumer journey",
                "Needs, pain points, gains, inputs, and outputs documented",
                "Journey evidence available for capability, requirements, and architecture decisions"
              ],
              "steps": [
                "Define customer persona",
                "Identify triggers for the journey",
                "Describe the journey's end",
                "Map journey steps with inputs/outputs",
                "Identify customer pains",
                "Summarize customer gains",
                "Define necessary inputs and resulting outputs",
                "Define interactions and processing expectations for each step"
              ],
              "canvasId": "customerJourneyCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "domainCanvas",
              "slug": "resources/domain-canvas",
              "title": "Domain Canvas",
              "description": "A modeling tool to define and communicate the key entities and relationships in your domain, ensuring semantic consistency across capabilities, integrations, APIs, data products, and services.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 152,
              "outcomes": [
                "Shared domain model and terminology",
                "Core entities, relationships, rules, and ownership clarified",
                "Semantic consistency across capabilities, integrations, APIs, data products, and services"
              ],
              "steps": [
                "Define core entities, their attributes, and relationships to create a shared conceptual understanding across capabilities, integrations, APIs, data products, and services."
              ],
              "canvasId": "domainCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capabilityValuePropositionCanvas",
              "slug": "resources/capability-value-proposition-canvas",
              "title": "Capability Value Proposition Canvas",
              "description": "A technology-agnostic canvas for mapping consumer tasks, gains, pains, and candidate reusable capabilities before selecting an implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 2.1,
              "outcomes": [
                "Clear reusable capability value proposition",
                "Consumer tasks, gains, and pains captured without assuming a technology",
                "Candidate reusable capabilities identified for architecture evaluation"
              ],
              "steps": [
                "List the consumer tasks and outcomes the capability should support.",
                "Identify gain-enabling capability features.",
                "Identify pain-relieving capability features.",
                "Group the features into candidate reusable capabilities."
              ],
              "canvasId": "capabilityValuePropositionCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capabilityBusinessModelCanvas",
              "slug": "resources/capability-business-model-canvas",
              "title": "Capability Business Model Canvas",
              "description": "A business model canvas for reusable capabilities, covering value, consumers, ownership, engagement, costs, and benefits without assuming an implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 3.1,
              "outcomes": [
                "Viable reusable capability operating model",
                "Ownership, consumers, channels, partners, and support needs clarified",
                "Costs and benefits visible before architecture commitment"
              ],
              "steps": [
                "Summarize the capability value proposition.",
                "Identify consumer segments and engagement channels.",
                "Define key activities, resources, and partners.",
                "Capture costs and benefits.",
                "Clarify ownership, funding, support, and lifecycle expectations.",
                "Validate the model with consumers, producers, and governance stakeholders."
              ],
              "canvasId": "capabilityBusinessModelCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "consumerExperienceRequirementsCanvas",
              "slug": "resources/consumer-experience-requirements-canvas",
              "title": "Consumer Experience Requirements Canvas",
              "description": "A requirements canvas for consumer experience and non-functional needs that should guide the later architecture and implementation-style decision.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 3.2,
              "outcomes": [
                "Technology-agnostic consumer and service requirements",
                "Experience and non-functional needs captured before design starts",
                "Architecture implications documented for implementation-style selection"
              ],
              "steps": [
                "Capture consumer goals and usage context.",
                "Document availability, timeliness, volume, performance, data quality, and consistency expectations.",
                "Document security, privacy, onboarding, change, observability, support, and recovery expectations.",
                "Summarize what the requirements imply for possible implementation styles."
              ],
              "canvasId": "consumerExperienceRequirementsCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "api-onboarding-best-practices",
              "slug": "resources/api-onboarding-best-practices",
              "title": "API Onboarding Best Practices",
              "description": "Best practices to streamline API consumer onboarding journeys with step-by-step registration, discovery, and first-call guidance.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 121,
              "outcomes": [
                "Shared understanding of the purpose and use of API Onboarding Best Practices",
                "A consistent approach to applying API Onboarding Best Practices",
                "Improved application of the related practices"
              ],
              "steps": [
                "Define the API consumer journey from discovery to troubleshooting, identifying key touchpoints and pain points.",
                "Develop onboarding processes and resources to help API consumers understand how to use APIs effectively.",
                "Document how consumers find and use the API, including onboarding processes and registration."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "businessImpactCanvas",
              "slug": "resources/business-impact-canvas",
              "title": "Business Impact Canvas",
              "description": "Identify business, availability, security, data, compliance, and operational risks that should shape architecture and platform decisions.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 4,
              "outcomes": [
                "Documented business and operational impact assessment",
                "Prioritized risks and mitigation actions",
                "Evidence for architecture and platform decisions"
              ],
              "steps": [
                "Availability Risks: Identify risks and impacts.",
                "Ways to Mitigate Availability Risks: Define mitigation measures.",
                "Security Risks: Document security-related risks.",
                "Ways to Mitigate Security Risks: Propose strategies to mitigate security risks.",
                "Data Risks: Identify risks to data accuracy or availability.",
                "Ways to Mitigate Data Risks: Plan strategies to address data risks."
              ],
              "canvasId": "businessImpactCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "locationsCanvas",
              "slug": "resources/location-canvas",
              "title": "Location Canvas",
              "description": "Map consumer, producer, system, data, network, regulatory, and trust-boundary locations to ensure compliance and performance across regions.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 6,
              "outcomes": [
                "Documented location, residency, network, and regulatory requirements",
                "Regional performance and accessibility constraints identified",
                "Data residency, trust boundaries, and applicable regulations clarified"
              ],
              "steps": [
                "Map locations of producers, source systems, platforms, and consumers.",
                "Document where consumers are located.",
                "Identify applicable regulations.",
                "Document where data must reside.",
                "Ensure the capability is accessible in all intended network regions.",
                "Validate network performance across regions."
              ],
              "canvasId": "locationsCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capacityCanvas",
              "slug": "resources/capacity-canvas",
              "title": "Capacity Canvas",
              "description": "Plan capacity for current and future demand, including volumes, peaks, latency, availability, scaling, caching, and rate limits for the selected capability and implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 7,
              "outcomes": [
                "Capacity requirements aligned with expected business demand",
                "Peak-load, availability, and growth assumptions documented",
                "Scaling, caching, and rate-limiting decisions defined"
              ],
              "steps": [
                "Document current business volumes",
                "Forecast future consumption trends",
                "Plan for peak load and availability requirements",
                "Define caching and rate-limiting strategies",
                "Propose scaling strategies"
              ],
              "canvasId": "capacityCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "interactionCanvas",
              "slug": "resources/interaction-canvas",
              "title": "Interaction Canvas",
              "description": "Define interactions, workflows, inputs, outputs, commands, queries, events, and expected responses to ensure a consistent consumer experience.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 9,
              "outcomes": [
                "Defined interaction model for the selected capability",
                "Inputs, outputs, commands, queries, events, and responses clarified",
                "Validation rules and interaction expectations agreed"
              ],
              "steps": [
                "Map interactions to user, consumer, or system tasks",
                "Define access points, operations, commands, queries, or events for each interaction",
                "Document inputs and outputs for each interaction.",
                "Specify validation rules and constraints",
                "Create interaction models for CRUD, query-driven, command-driven, and event-driven interactions"
              ],
              "canvasId": "interactionCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            }
          ],
          "promptIds": [
            "capability-owner:facilitate-station",
            "capability-owner:use-resources",
            "capability-owner:next-actions"
          ]
        },
        {
          "id": "compliance-specialist",
          "stakeholderId": "compliance-specialist",
          "title": "Compliance and Legal Specialist",
          "summary": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
          "stakeholder": {
            "id": "compliance-specialist",
            "sourceKey": "compliance-specialist",
            "sourceStakeholderId": "compliance-specialist",
            "title": "Compliance and Legal Specialist",
            "description": "Clarifies legal, privacy, regulatory, and contractual requirements that affect the capability, API, interface, or automation.",
            "involvement": ""
          },
          "cycles": [
            {
              "id": "capability-productization-cycle",
              "title": "Capability Productization Cycle",
              "description": "A cycle for turning business capabilities into reusable digital capabilities before selecting the implementation style."
            },
            {
              "id": "api-productization-cycle",
              "title": "API Productization Cycle",
              "description": "The API-focused APIOps Cycles journey for productizing, designing, delivering, publishing, and improving APIs."
            },
            {
              "id": "integration-productization-cycle",
              "title": "Integration Productization Cycle",
              "description": "A cycle for productizing reusable integration capabilities before selecting the implementation style."
            },
            {
              "id": "automation-cycle",
              "title": "Automation Cycle",
              "description": "A cycle for identifying, designing, delivering, enabling, and improving automation opportunities."
            }
          ],
          "stations": [
            {
              "id": "api-product-strategy",
              "title": "Strategy",
              "description": "Frame the business need as a reusable capability before choosing the implementation style."
            },
            {
              "id": "api-platform-architecture",
              "title": "Architecture & Platform Decisions",
              "description": "Use requirements and constraints to decide the right architecture pattern and enabling platform capabilities."
            },
            {
              "id": "api-delivery",
              "title": "Delivery & Operations",
              "description": "Deliver the selected implementation style with appropriate engineering, testing, security, automation, and operational practices."
            },
            {
              "id": "api-audit",
              "title": "Quality & Readiness Assurance",
              "description": "Audit the capability interface contract, controls, support model, observability, documentation, and lifecycle readiness before release."
            },
            {
              "id": "monitoring-and-improving",
              "title": "Monitoring & Improvement",
              "description": "Monitor usage, reliability, data quality, consumer outcomes, operational cost, and reuse opportunities after release."
            },
            {
              "id": "api-design",
              "title": "Solution & Interface Design",
              "description": "Design the interface contract and interaction model after the architecture choice is justified."
            },
            {
              "id": "api-publishing",
              "title": "Publishing & Enablement",
              "description": "Publish reusable capability information so consumers can discover, request, onboard, use, and get support."
            },
            {
              "id": "api-consumer-experience",
              "title": "Consumer Requirements & Onboarding",
              "description": "Capture consumer onboarding, standards, non-functional requirements, service expectations, constraints, security needs, allowed protocols, data freshness, SLAs, observability, recovery, adoption requirements, and producer responsibilities."
            }
          ],
          "canvases": [
            {
              "id": "customerJourneyCanvas",
              "title": "Customer Journey Canvas"
            },
            {
              "id": "domainCanvas",
              "title": "Domain Canvas"
            },
            {
              "id": "capabilityValuePropositionCanvas",
              "title": "Capability Value Proposition Canvas"
            },
            {
              "id": "capabilityBusinessModelCanvas",
              "title": "Capability Business Model Canvas"
            },
            {
              "id": "businessImpactCanvas",
              "title": "Business Impact Canvas"
            },
            {
              "id": "locationsCanvas",
              "title": "Locations Canvas"
            },
            {
              "id": "capacityCanvas",
              "title": "Capacity Canvas"
            },
            {
              "id": "interactionCanvas",
              "title": "Interaction Canvas"
            },
            {
              "id": "consumerExperienceRequirementsCanvas",
              "title": "Consumer Experience Requirements Canvas"
            },
            {
              "id": "apiValuePropositionCanvas",
              "title": "API Value Proposition Canvas"
            },
            {
              "id": "apiBusinessModelCanvas",
              "title": "API Business Model Canvas"
            },
            {
              "id": "restCanvas",
              "title": "REST Canvas"
            },
            {
              "id": "eventCanvas",
              "title": "Event Canvas"
            },
            {
              "id": "graphqlCanvas",
              "title": "GraphQL Canvas"
            }
          ],
          "decisions": [
            "Map the customer or partner journey that creates the capability need and reveals tasks, pains, gains, inputs, outputs, and decision points.",
            "Define the core entities, attributes, relationships, ownership, and business rules that the capability must respect.",
            "Use the Capability Value Proposition Canvas to capture consumer tasks, gains, pains, and reusable capability features without naming the delivery technology too early.",
            "Use the Capability Business Model Canvas to clarify ownership, partners, channels, costs, benefits, support, and lifecycle expectations for the reusable capability.",
            "Use shared journey, domain, value proposition, and business model canvases to gather technology-agnostic requirements and decide whether the capability should be reusable.",
            "Integration and API work often jumps too quickly to a technical pattern. This station keeps the team focused on the business journey, domain meaning, value, reuse potential, ownership, and viability before selecting APIs, events, files, streams, data products, or direct integration."
          ],
          "outputs": [
            "A technology-agnostic capability opportunity statement",
            "Shared understanding of consumers, producers, domain concepts, and reuse potential",
            "A capability value proposition and business model before architecture selection",
            "design-artifact",
            "documentation",
            "research",
            "roadmap",
            "A justified architecture choice"
          ],
          "recommendedResources": [
            {
              "id": "customerJourneyCanvas",
              "slug": "resources/customer-journey-canvas",
              "title": "Customer Journey Canvas",
              "description": "Map customer, partner, or consumer journeys to identify needs, pain points, gains, inputs, outputs, and experience expectations.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 1,
              "outcomes": [
                "Shared understanding of the customer, partner, or consumer journey",
                "Needs, pain points, gains, inputs, and outputs documented",
                "Journey evidence available for capability, requirements, and architecture decisions"
              ],
              "steps": [
                "Define customer persona",
                "Identify triggers for the journey",
                "Describe the journey's end",
                "Map journey steps with inputs/outputs",
                "Identify customer pains",
                "Summarize customer gains",
                "Define necessary inputs and resulting outputs",
                "Define interactions and processing expectations for each step"
              ],
              "canvasId": "customerJourneyCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "domainCanvas",
              "slug": "resources/domain-canvas",
              "title": "Domain Canvas",
              "description": "A modeling tool to define and communicate the key entities and relationships in your domain, ensuring semantic consistency across capabilities, integrations, APIs, data products, and services.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 152,
              "outcomes": [
                "Shared domain model and terminology",
                "Core entities, relationships, rules, and ownership clarified",
                "Semantic consistency across capabilities, integrations, APIs, data products, and services"
              ],
              "steps": [
                "Define core entities, their attributes, and relationships to create a shared conceptual understanding across capabilities, integrations, APIs, data products, and services."
              ],
              "canvasId": "domainCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capabilityValuePropositionCanvas",
              "slug": "resources/capability-value-proposition-canvas",
              "title": "Capability Value Proposition Canvas",
              "description": "A technology-agnostic canvas for mapping consumer tasks, gains, pains, and candidate reusable capabilities before selecting an implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 2.1,
              "outcomes": [
                "Clear reusable capability value proposition",
                "Consumer tasks, gains, and pains captured without assuming a technology",
                "Candidate reusable capabilities identified for architecture evaluation"
              ],
              "steps": [
                "List the consumer tasks and outcomes the capability should support.",
                "Identify gain-enabling capability features.",
                "Identify pain-relieving capability features.",
                "Group the features into candidate reusable capabilities."
              ],
              "canvasId": "capabilityValuePropositionCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capabilityBusinessModelCanvas",
              "slug": "resources/capability-business-model-canvas",
              "title": "Capability Business Model Canvas",
              "description": "A business model canvas for reusable capabilities, covering value, consumers, ownership, engagement, costs, and benefits without assuming an implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 3.1,
              "outcomes": [
                "Viable reusable capability operating model",
                "Ownership, consumers, channels, partners, and support needs clarified",
                "Costs and benefits visible before architecture commitment"
              ],
              "steps": [
                "Summarize the capability value proposition.",
                "Identify consumer segments and engagement channels.",
                "Define key activities, resources, and partners.",
                "Capture costs and benefits.",
                "Clarify ownership, funding, support, and lifecycle expectations.",
                "Validate the model with consumers, producers, and governance stakeholders."
              ],
              "canvasId": "capabilityBusinessModelCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "businessImpactCanvas",
              "slug": "resources/business-impact-canvas",
              "title": "Business Impact Canvas",
              "description": "Identify business, availability, security, data, compliance, and operational risks that should shape architecture and platform decisions.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 4,
              "outcomes": [
                "Documented business and operational impact assessment",
                "Prioritized risks and mitigation actions",
                "Evidence for architecture and platform decisions"
              ],
              "steps": [
                "Availability Risks: Identify risks and impacts.",
                "Ways to Mitigate Availability Risks: Define mitigation measures.",
                "Security Risks: Document security-related risks.",
                "Ways to Mitigate Security Risks: Propose strategies to mitigate security risks.",
                "Data Risks: Identify risks to data accuracy or availability.",
                "Ways to Mitigate Data Risks: Plan strategies to address data risks."
              ],
              "canvasId": "businessImpactCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "locationsCanvas",
              "slug": "resources/location-canvas",
              "title": "Location Canvas",
              "description": "Map consumer, producer, system, data, network, regulatory, and trust-boundary locations to ensure compliance and performance across regions.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 6,
              "outcomes": [
                "Documented location, residency, network, and regulatory requirements",
                "Regional performance and accessibility constraints identified",
                "Data residency, trust boundaries, and applicable regulations clarified"
              ],
              "steps": [
                "Map locations of producers, source systems, platforms, and consumers.",
                "Document where consumers are located.",
                "Identify applicable regulations.",
                "Document where data must reside.",
                "Ensure the capability is accessible in all intended network regions.",
                "Validate network performance across regions."
              ],
              "canvasId": "locationsCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capacityCanvas",
              "slug": "resources/capacity-canvas",
              "title": "Capacity Canvas",
              "description": "Plan capacity for current and future demand, including volumes, peaks, latency, availability, scaling, caching, and rate limits for the selected capability and implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 7,
              "outcomes": [
                "Capacity requirements aligned with expected business demand",
                "Peak-load, availability, and growth assumptions documented",
                "Scaling, caching, and rate-limiting decisions defined"
              ],
              "steps": [
                "Document current business volumes",
                "Forecast future consumption trends",
                "Plan for peak load and availability requirements",
                "Define caching and rate-limiting strategies",
                "Propose scaling strategies"
              ],
              "canvasId": "capacityCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "api-development-best-practices",
              "slug": "resources/api-development-best-practices",
              "title": "API Development Best Practices",
              "description": "Implementation guidance for turning a validated API interface contract into a consistent, maintainable API codebase using standard libraries, reusable patterns, and aligned development workflows.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 112,
              "outcomes": [
                "Shared understanding of the purpose and use of API Development Best Practices",
                "A consistent approach to applying API Development Best Practices",
                "Improved application of the related practices"
              ],
              "steps": [
                "Apply these practices to the validated API interface contract and implementation plan before coding begins.",
                "Use established frameworks, libraries, and coding standards to implement the contract consistently and maintainably."
              ],
              "canvasId": null,
              "sourcePath": "src/snippets/api-design-principles-guidance.md",
              "sourceUrl": null,
              "contentMarkdown": "## How to start the API Delivery work based on the previous phases (\"stations\")\r\n\r\nUse this guidance at the start of `API Delivery` after the API contract (e.g. OpenAPI) and the key outputs from earlier stations have been reviewed and accepted.\r\n\r\nThe goal is not to invent implementation in isolation. The goal is to turn the agreed outputs from earlier stations into concrete code structure, validation rules, runtime behavior, and API product delivery decisions.\r\n\r\n---\r\n\r\n### 1. Start From The Validated Contract\r\n\r\n- Treat the validated API contract as the main reference point for implementation decisions.\r\n- Keep the contract and implementation aligned throughout the API product delivery.\r\n- Use the contract to drive request validation, response mapping, documentation, and tests.\r\n\r\n---\r\n\r\n### 2. Use Domain Outputs To Preserve Business Meaning\r\n\r\n- Use the `Domain Canvas` outputs to guide naming, how the implementation is split into clear business responsibilities, and how different backend systems are connected without exposing their differences.\r\n- Preserve the validated meanings of entities, attributes, statuses, and source-of-truth rules.\r\n- Avoid leaking backend-specific models or inconsistencies into the public API.\r\n\r\n---\r\n\r\n### 3. Use Journey Outputs To Preserve Critical Flows\r\n\r\n- Use the `Customer Journey Canvas` outputs to identify which user flows are most important to support first.\r\n- Use the `API Consumer Experience` outputs to keep the API understandable, predictable, and easy to integrate.\r\n- Let the agreed journey priorities decide which implementation paths need the highest reliability, lowest latency, clearest errors, and strongest operational focus.\r\n\r\n---\r\n\r\n### 4. Use Value Proposition Outputs To Preserve Consumer Value\r\n\r\n- Use the `API Value Proposition Canvas` outputs to keep the implementation focused on the agreed pains, gains, and API features.\r\n- Preserve the field meanings, behavior, and promises that made the API valuable in the earlier stations.\r\n- Ensure error handling, freshness, and naming support both the intended developer experience and the business use case.\r\n\r\n---\r\n\r\n### 5. Use Architecture Outputs To Shape Runtime Decisions\r\n\r\n- Use the `Business Impact Canvas` outputs to guide resilience, timeout, fallback, and degradation decisions.\r\n- Use the `Locations Canvas` outputs to guide network boundaries, trust boundaries, access paths, and deployment constraints.\r\n- Use the `Capacity Canvas` outputs to guide rate limits, caching, scaling, and peak-load behavior.\r\n- Use the `API Metrics And Analytics` guidance to decide what must be observed from the first implementation onward.\r\n\r\n---\r\n\r\n### 6. Use Interaction And Protocol Design Outputs To Shape Code Structure\r\n\r\n- Use the `Interaction Canvas` outputs to avoid implementing unsupported interaction styles too early.\r\n- Use the `REST`, `Event`, or `GraphQL` design outputs to shape protocol-specific request, response, and validation behavior.\r\n- Reflect the selected interaction style clearly in code structure, responsibilities, and testing strategy.\r\n\r\n---\r\n\r\n### 7. Use Audit Outputs To Improve Delivery Before Coding Goes Too Far\r\n\r\n- Use the audit findings to remove ambiguity before implementation spreads across the codebase.\r\n- Fix unclear request rules, missing validation, weak error contracts, and operational gaps early.\r\n- Treat audit as a design-improvement loop before production, not only as a final decision gate.\r\n\r\n---\r\n\r\n### 8. Apply The Guidance, Then Summarize\r\n\r\n- Apply this guidance to the current API and implementation plan.\r\n- Summarize the implications for code structure, request validation, source integration, security, monitoring and alerts, and testing.\r\n- Do not create a separate delivery artifact unless the team or user specifically needs one.\r\n",
              "draft": true
            },
            {
              "id": "api-testing-best-practices",
              "slug": "resources/api-testing-best-practices",
              "title": "API Testing Best Practices",
              "description": "Guidelines for implementing automated functional, performance, and security testing throughout the API lifecycle.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 133,
              "outcomes": [
                "Shared understanding of the purpose and use of API Testing Best Practices",
                "A consistent approach to applying API Testing Best Practices",
                "Improved application of the related practices"
              ],
              "steps": [
                "Test APIs for functionality, security, and performance using automated testing tools.",
                "Integrate functional and non-functional testing into the CI/CD pipeline to ensure APIs meet quality standards.",
                "Use automated testing tools to validate API functionality, security, and performance."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "apiops-CI-CD-for-apis",
              "slug": "resources/apiops-CI-CD-for-apis",
              "title": "APIOps CI/CD For APIs",
              "description": "Deployment guidance that integrates API lifecycle tasks—design, testing, governance—into continuous integration and delivery pipelines.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 140,
              "outcomes": [
                "Shared understanding of the purpose and use of APIOps CI/CD For APIs",
                "A consistent approach to applying APIOps CI/CD For APIs",
                "Improved application of the related practices"
              ],
              "steps": [
                "Use CI/CD pipelines to automate build, test, and deployment processes, ensuring consistent quality and traceability.",
                "Integrate automated tests into the CI/CD pipeline to ensure continuous validation of API quality.",
                "Implement deployment strategies (e.g., blue-green deployments, canary releases) to minimize risks during API releases.",
                "Establish a habit of reviewing metrics and planning continuous improvement activities."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            }
          ],
          "promptIds": [
            "compliance-specialist:facilitate-station",
            "compliance-specialist:use-resources",
            "compliance-specialist:next-actions"
          ]
        },
        {
          "id": "customer-specialist",
          "stakeholderId": "customer-specialist",
          "title": "Customer or Partner Representative",
          "summary": "Contributes the business customer or partner perspective for the journey, value, and collaboration model.",
          "stakeholder": {
            "id": "customer-specialist",
            "sourceKey": "customer-specialist",
            "sourceStakeholderId": "customer-specialist",
            "title": "Customer or Partner Representative",
            "description": "Contributes the business customer or partner perspective for the journey, value, and collaboration model.",
            "involvement": ""
          },
          "cycles": [
            {
              "id": "capability-productization-cycle",
              "title": "Capability Productization Cycle",
              "description": "A cycle for turning business capabilities into reusable digital capabilities before selecting the implementation style."
            },
            {
              "id": "api-productization-cycle",
              "title": "API Productization Cycle",
              "description": "The API-focused APIOps Cycles journey for productizing, designing, delivering, publishing, and improving APIs."
            },
            {
              "id": "integration-productization-cycle",
              "title": "Integration Productization Cycle",
              "description": "A cycle for productizing reusable integration capabilities before selecting the implementation style."
            },
            {
              "id": "automation-cycle",
              "title": "Automation Cycle",
              "description": "A cycle for identifying, designing, delivering, enabling, and improving automation opportunities."
            }
          ],
          "stations": [
            {
              "id": "api-product-strategy",
              "title": "Strategy",
              "description": "Frame the business need as a reusable capability before choosing the implementation style."
            },
            {
              "id": "api-consumer-experience",
              "title": "Consumer Requirements & Onboarding",
              "description": "Capture consumer onboarding, standards, non-functional requirements, service expectations, constraints, security needs, allowed protocols, data freshness, SLAs, observability, recovery, adoption requirements, and producer responsibilities."
            }
          ],
          "canvases": [
            {
              "id": "customerJourneyCanvas",
              "title": "Customer Journey Canvas"
            },
            {
              "id": "domainCanvas",
              "title": "Domain Canvas"
            },
            {
              "id": "capabilityValuePropositionCanvas",
              "title": "Capability Value Proposition Canvas"
            },
            {
              "id": "capabilityBusinessModelCanvas",
              "title": "Capability Business Model Canvas"
            },
            {
              "id": "consumerExperienceRequirementsCanvas",
              "title": "Consumer Experience Requirements Canvas"
            },
            {
              "id": "apiValuePropositionCanvas",
              "title": "API Value Proposition Canvas"
            },
            {
              "id": "apiBusinessModelCanvas",
              "title": "API Business Model Canvas"
            }
          ],
          "decisions": [
            "Map the customer or partner journey that creates the capability need and reveals tasks, pains, gains, inputs, outputs, and decision points.",
            "Define the core entities, attributes, relationships, ownership, and business rules that the capability must respect.",
            "Use the Capability Value Proposition Canvas to capture consumer tasks, gains, pains, and reusable capability features without naming the delivery technology too early.",
            "Use the Capability Business Model Canvas to clarify ownership, partners, channels, costs, benefits, support, and lifecycle expectations for the reusable capability.",
            "Use shared journey, domain, value proposition, and business model canvases to gather technology-agnostic requirements and decide whether the capability should be reusable.",
            "Integration and API work often jumps too quickly to a technical pattern. This station keeps the team focused on the business journey, domain meaning, value, reuse potential, ownership, and viability before selecting APIs, events, files, streams, data products, or direct integration."
          ],
          "outputs": [
            "A technology-agnostic capability opportunity statement",
            "Shared understanding of consumers, producers, domain concepts, and reuse potential",
            "A capability value proposition and business model before architecture selection",
            "design-artifact",
            "documentation",
            "research",
            "roadmap",
            "Documented consumer requirements and onboarding expectations"
          ],
          "recommendedResources": [
            {
              "id": "customerJourneyCanvas",
              "slug": "resources/customer-journey-canvas",
              "title": "Customer Journey Canvas",
              "description": "Map customer, partner, or consumer journeys to identify needs, pain points, gains, inputs, outputs, and experience expectations.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 1,
              "outcomes": [
                "Shared understanding of the customer, partner, or consumer journey",
                "Needs, pain points, gains, inputs, and outputs documented",
                "Journey evidence available for capability, requirements, and architecture decisions"
              ],
              "steps": [
                "Define customer persona",
                "Identify triggers for the journey",
                "Describe the journey's end",
                "Map journey steps with inputs/outputs",
                "Identify customer pains",
                "Summarize customer gains",
                "Define necessary inputs and resulting outputs",
                "Define interactions and processing expectations for each step"
              ],
              "canvasId": "customerJourneyCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "domainCanvas",
              "slug": "resources/domain-canvas",
              "title": "Domain Canvas",
              "description": "A modeling tool to define and communicate the key entities and relationships in your domain, ensuring semantic consistency across capabilities, integrations, APIs, data products, and services.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 152,
              "outcomes": [
                "Shared domain model and terminology",
                "Core entities, relationships, rules, and ownership clarified",
                "Semantic consistency across capabilities, integrations, APIs, data products, and services"
              ],
              "steps": [
                "Define core entities, their attributes, and relationships to create a shared conceptual understanding across capabilities, integrations, APIs, data products, and services."
              ],
              "canvasId": "domainCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capabilityValuePropositionCanvas",
              "slug": "resources/capability-value-proposition-canvas",
              "title": "Capability Value Proposition Canvas",
              "description": "A technology-agnostic canvas for mapping consumer tasks, gains, pains, and candidate reusable capabilities before selecting an implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 2.1,
              "outcomes": [
                "Clear reusable capability value proposition",
                "Consumer tasks, gains, and pains captured without assuming a technology",
                "Candidate reusable capabilities identified for architecture evaluation"
              ],
              "steps": [
                "List the consumer tasks and outcomes the capability should support.",
                "Identify gain-enabling capability features.",
                "Identify pain-relieving capability features.",
                "Group the features into candidate reusable capabilities."
              ],
              "canvasId": "capabilityValuePropositionCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capabilityBusinessModelCanvas",
              "slug": "resources/capability-business-model-canvas",
              "title": "Capability Business Model Canvas",
              "description": "A business model canvas for reusable capabilities, covering value, consumers, ownership, engagement, costs, and benefits without assuming an implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 3.1,
              "outcomes": [
                "Viable reusable capability operating model",
                "Ownership, consumers, channels, partners, and support needs clarified",
                "Costs and benefits visible before architecture commitment"
              ],
              "steps": [
                "Summarize the capability value proposition.",
                "Identify consumer segments and engagement channels.",
                "Define key activities, resources, and partners.",
                "Capture costs and benefits.",
                "Clarify ownership, funding, support, and lifecycle expectations.",
                "Validate the model with consumers, producers, and governance stakeholders."
              ],
              "canvasId": "capabilityBusinessModelCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "consumerExperienceRequirementsCanvas",
              "slug": "resources/consumer-experience-requirements-canvas",
              "title": "Consumer Experience Requirements Canvas",
              "description": "A requirements canvas for consumer experience and non-functional needs that should guide the later architecture and implementation-style decision.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 3.2,
              "outcomes": [
                "Technology-agnostic consumer and service requirements",
                "Experience and non-functional needs captured before design starts",
                "Architecture implications documented for implementation-style selection"
              ],
              "steps": [
                "Capture consumer goals and usage context.",
                "Document availability, timeliness, volume, performance, data quality, and consistency expectations.",
                "Document security, privacy, onboarding, change, observability, support, and recovery expectations.",
                "Summarize what the requirements imply for possible implementation styles."
              ],
              "canvasId": "consumerExperienceRequirementsCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "api-onboarding-best-practices",
              "slug": "resources/api-onboarding-best-practices",
              "title": "API Onboarding Best Practices",
              "description": "Best practices to streamline API consumer onboarding journeys with step-by-step registration, discovery, and first-call guidance.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 121,
              "outcomes": [
                "Shared understanding of the purpose and use of API Onboarding Best Practices",
                "A consistent approach to applying API Onboarding Best Practices",
                "Improved application of the related practices"
              ],
              "steps": [
                "Define the API consumer journey from discovery to troubleshooting, identifying key touchpoints and pain points.",
                "Develop onboarding processes and resources to help API consumers understand how to use APIs effectively.",
                "Document how consumers find and use the API, including onboarding processes and registration."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "apiValuePropositionCanvas",
              "slug": "resources/api-value-proposition-canvas",
              "title": "API Value Proposition Canvas",
              "description": "Align API features with user needs by mapping tasks, pains, and gains to API products.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 2,
              "outcomes": [
                "Focused feature development",
                "Alignment with user needs",
                "Improved API consumer satisfaction"
              ],
              "steps": [
                "List user journey tasks",
                "Identify features delivering expected gains",
                "Define features addressing challenges",
                "Map features to API products"
              ],
              "canvasId": "apiValuePropositionCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "apiBusinessModelCanvas",
              "slug": "resources/api-business-model-canvas",
              "title": "API Business Model Canvas",
              "description": "Strategically assess API business viability by mapping value propositions, consumer segments, and key resources.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 3,
              "outcomes": [
                "Clear business strategy for APIs",
                "Identification of key resources and partners",
                "Alignment of API features with business goals"
              ],
              "steps": [
                "Summarize the API's value proposition",
                "Define consumer segments",
                "Identify developer relations strategies",
                "Map distribution channels",
                "Document key resources and activities",
                "Identify key partners and stakeholders",
                "Highlight benefits and costs"
              ],
              "canvasId": "apiBusinessModelCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            }
          ],
          "promptIds": [
            "customer-specialist:facilitate-station",
            "customer-specialist:use-resources",
            "customer-specialist:next-actions"
          ]
        },
        {
          "id": "api-engineer",
          "stakeholderId": "api-engineer",
          "title": "Delivery Engineer",
          "summary": "Owns implementation, automation, testing, and release flow concerns needed to deliver the capability, API, or automation reliably.",
          "stakeholder": {
            "id": "api-engineer",
            "sourceKey": "api-engineer",
            "sourceStakeholderId": "api-engineer",
            "title": "Delivery Engineer",
            "description": "Owns implementation, automation, testing, and release flow concerns needed to deliver the capability, API, or automation reliably.",
            "involvement": ""
          },
          "cycles": [
            {
              "id": "capability-productization-cycle",
              "title": "Capability Productization Cycle",
              "description": "A cycle for turning business capabilities into reusable digital capabilities before selecting the implementation style."
            },
            {
              "id": "api-productization-cycle",
              "title": "API Productization Cycle",
              "description": "The API-focused APIOps Cycles journey for productizing, designing, delivering, publishing, and improving APIs."
            },
            {
              "id": "integration-productization-cycle",
              "title": "Integration Productization Cycle",
              "description": "A cycle for productizing reusable integration capabilities before selecting the implementation style."
            },
            {
              "id": "automation-cycle",
              "title": "Automation Cycle",
              "description": "A cycle for identifying, designing, delivering, enabling, and improving automation opportunities."
            }
          ],
          "stations": [
            {
              "id": "api-delivery",
              "title": "Delivery & Operations",
              "description": "Deliver the selected implementation style with appropriate engineering, testing, security, automation, and operational practices."
            },
            {
              "id": "api-audit",
              "title": "Quality & Readiness Assurance",
              "description": "Audit the capability interface contract, controls, support model, observability, documentation, and lifecycle readiness before release."
            },
            {
              "id": "api-platform-architecture",
              "title": "Architecture & Platform Decisions",
              "description": "Use requirements and constraints to decide the right architecture pattern and enabling platform capabilities."
            },
            {
              "id": "api-design",
              "title": "Solution & Interface Design",
              "description": "Design the interface contract and interaction model after the architecture choice is justified."
            },
            {
              "id": "api-publishing",
              "title": "Publishing & Enablement",
              "description": "Publish reusable capability information so consumers can discover, request, onboard, use, and get support."
            },
            {
              "id": "monitoring-and-improving",
              "title": "Monitoring & Improvement",
              "description": "Monitor usage, reliability, data quality, consumer outcomes, operational cost, and reuse opportunities after release."
            }
          ],
          "canvases": [
            {
              "id": "businessImpactCanvas",
              "title": "Business Impact Canvas"
            },
            {
              "id": "locationsCanvas",
              "title": "Locations Canvas"
            },
            {
              "id": "capacityCanvas",
              "title": "Capacity Canvas"
            },
            {
              "id": "domainCanvas",
              "title": "Domain Canvas"
            },
            {
              "id": "interactionCanvas",
              "title": "Interaction Canvas"
            },
            {
              "id": "restCanvas",
              "title": "REST Canvas"
            },
            {
              "id": "eventCanvas",
              "title": "Event Canvas"
            },
            {
              "id": "graphqlCanvas",
              "title": "GraphQL Canvas"
            }
          ],
          "decisions": [
            "Use development best practices to implement the validated interface contract with established frameworks, libraries, and team standards.",
            "Build the implementation from the validated interface contract using established frameworks, libraries, and team standards.",
            "Use testing guidance to verify functionality, data quality, compatibility, security, performance, resilience, and recovery expectations.",
            "Use CI/CD guidance to automate build, test, deployment, configuration, and traceability.",
            "Use security guidance to protect data, access, credentials, and platform boundaries.",
            "Use the audit checklist to ensure the solution meets functional and non-functional requirements, including security, performance, and compliance."
          ],
          "outputs": [
            "A delivered capability aligned with the validated interface contract",
            "Automated testing, deployment, and environment controls",
            "Security, operations, and quality practices appropriate to the chosen pattern",
            "Traceable delivery and release controls",
            "implementation",
            "pipeline-config",
            "test-report",
            "security-report"
          ],
          "recommendedResources": [
            {
              "id": "api-development-best-practices",
              "slug": "resources/api-development-best-practices",
              "title": "API Development Best Practices",
              "description": "Implementation guidance for turning a validated API interface contract into a consistent, maintainable API codebase using standard libraries, reusable patterns, and aligned development workflows.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 112,
              "outcomes": [
                "Shared understanding of the purpose and use of API Development Best Practices",
                "A consistent approach to applying API Development Best Practices",
                "Improved application of the related practices"
              ],
              "steps": [
                "Apply these practices to the validated API interface contract and implementation plan before coding begins.",
                "Use established frameworks, libraries, and coding standards to implement the contract consistently and maintainably."
              ],
              "canvasId": null,
              "sourcePath": "src/snippets/api-design-principles-guidance.md",
              "sourceUrl": null,
              "contentMarkdown": "## How to start the API Delivery work based on the previous phases (\"stations\")\r\n\r\nUse this guidance at the start of `API Delivery` after the API contract (e.g. OpenAPI) and the key outputs from earlier stations have been reviewed and accepted.\r\n\r\nThe goal is not to invent implementation in isolation. The goal is to turn the agreed outputs from earlier stations into concrete code structure, validation rules, runtime behavior, and API product delivery decisions.\r\n\r\n---\r\n\r\n### 1. Start From The Validated Contract\r\n\r\n- Treat the validated API contract as the main reference point for implementation decisions.\r\n- Keep the contract and implementation aligned throughout the API product delivery.\r\n- Use the contract to drive request validation, response mapping, documentation, and tests.\r\n\r\n---\r\n\r\n### 2. Use Domain Outputs To Preserve Business Meaning\r\n\r\n- Use the `Domain Canvas` outputs to guide naming, how the implementation is split into clear business responsibilities, and how different backend systems are connected without exposing their differences.\r\n- Preserve the validated meanings of entities, attributes, statuses, and source-of-truth rules.\r\n- Avoid leaking backend-specific models or inconsistencies into the public API.\r\n\r\n---\r\n\r\n### 3. Use Journey Outputs To Preserve Critical Flows\r\n\r\n- Use the `Customer Journey Canvas` outputs to identify which user flows are most important to support first.\r\n- Use the `API Consumer Experience` outputs to keep the API understandable, predictable, and easy to integrate.\r\n- Let the agreed journey priorities decide which implementation paths need the highest reliability, lowest latency, clearest errors, and strongest operational focus.\r\n\r\n---\r\n\r\n### 4. Use Value Proposition Outputs To Preserve Consumer Value\r\n\r\n- Use the `API Value Proposition Canvas` outputs to keep the implementation focused on the agreed pains, gains, and API features.\r\n- Preserve the field meanings, behavior, and promises that made the API valuable in the earlier stations.\r\n- Ensure error handling, freshness, and naming support both the intended developer experience and the business use case.\r\n\r\n---\r\n\r\n### 5. Use Architecture Outputs To Shape Runtime Decisions\r\n\r\n- Use the `Business Impact Canvas` outputs to guide resilience, timeout, fallback, and degradation decisions.\r\n- Use the `Locations Canvas` outputs to guide network boundaries, trust boundaries, access paths, and deployment constraints.\r\n- Use the `Capacity Canvas` outputs to guide rate limits, caching, scaling, and peak-load behavior.\r\n- Use the `API Metrics And Analytics` guidance to decide what must be observed from the first implementation onward.\r\n\r\n---\r\n\r\n### 6. Use Interaction And Protocol Design Outputs To Shape Code Structure\r\n\r\n- Use the `Interaction Canvas` outputs to avoid implementing unsupported interaction styles too early.\r\n- Use the `REST`, `Event`, or `GraphQL` design outputs to shape protocol-specific request, response, and validation behavior.\r\n- Reflect the selected interaction style clearly in code structure, responsibilities, and testing strategy.\r\n\r\n---\r\n\r\n### 7. Use Audit Outputs To Improve Delivery Before Coding Goes Too Far\r\n\r\n- Use the audit findings to remove ambiguity before implementation spreads across the codebase.\r\n- Fix unclear request rules, missing validation, weak error contracts, and operational gaps early.\r\n- Treat audit as a design-improvement loop before production, not only as a final decision gate.\r\n\r\n---\r\n\r\n### 8. Apply The Guidance, Then Summarize\r\n\r\n- Apply this guidance to the current API and implementation plan.\r\n- Summarize the implications for code structure, request validation, source integration, security, monitoring and alerts, and testing.\r\n- Do not create a separate delivery artifact unless the team or user specifically needs one.\r\n",
              "draft": true
            },
            {
              "id": "api-testing-best-practices",
              "slug": "resources/api-testing-best-practices",
              "title": "API Testing Best Practices",
              "description": "Guidelines for implementing automated functional, performance, and security testing throughout the API lifecycle.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 133,
              "outcomes": [
                "Shared understanding of the purpose and use of API Testing Best Practices",
                "A consistent approach to applying API Testing Best Practices",
                "Improved application of the related practices"
              ],
              "steps": [
                "Test APIs for functionality, security, and performance using automated testing tools.",
                "Integrate functional and non-functional testing into the CI/CD pipeline to ensure APIs meet quality standards.",
                "Use automated testing tools to validate API functionality, security, and performance."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "apiops-CI-CD-for-apis",
              "slug": "resources/apiops-CI-CD-for-apis",
              "title": "APIOps CI/CD For APIs",
              "description": "Deployment guidance that integrates API lifecycle tasks—design, testing, governance—into continuous integration and delivery pipelines.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 140,
              "outcomes": [
                "Shared understanding of the purpose and use of APIOps CI/CD For APIs",
                "A consistent approach to applying APIOps CI/CD For APIs",
                "Improved application of the related practices"
              ],
              "steps": [
                "Use CI/CD pipelines to automate build, test, and deployment processes, ensuring consistent quality and traceability.",
                "Integrate automated tests into the CI/CD pipeline to ensure continuous validation of API quality.",
                "Implement deployment strategies (e.g., blue-green deployments, canary releases) to minimize risks during API releases.",
                "Establish a habit of reviewing metrics and planning continuous improvement activities."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "api-audit-checklist",
              "slug": "resources/api-audit-checklist",
              "title": "API Audit Checklist",
              "description": "A lifecycle-based checklist to verify API readiness across design, delivery, publishing, and compliance using defined audit criteria and evidence.",
              "category": "checklist",
              "icon": "check-box-outline",
              "order": 13,
              "outcomes": [
                "Shared understanding of the purpose and use of API Audit Checklist",
                "A consistent approach to applying API Audit Checklist",
                "Improved application of the related practices"
              ],
              "steps": [
                "Use the API Audit Checklist to ensure the API design meets functional and non-functional requirements, including security, performance, and compliance.",
                "Conduct audits to assess lifecycle coverage and verify that the API meets business, design, and operational standards.",
                "Ensure that documentation, security models, gateway configuration, and legal requirements are clearly defined, validated, and supported by evidence."
              ],
              "canvasId": null,
              "sourcePath": "src/snippets/api-audit-checklist.json",
              "sourceUrl": null,
              "contentMarkdown": "{\r\n  \"profiles\": {\r\n    \"read-only\": {\r\n      \"description\": \"API profile that is read-only and does not allow create, update, or delete operations.\"\r\n    },\r\n    \"full-crud\": {\r\n      \"description\": \"General API profile that allows create, update, and delete operations.\"\r\n    }\r\n  },\r\n  \"lifecycleStages\": [\r\n    {\r\n      \"id\": \"strategy\",\r\n      \"title\": \"Strategy\",\r\n      \"readinessLabel\": \"Strategy is Ready When...\",\r\n      \"order\": 1\r\n    },\r\n    {\r\n      \"id\": \"architecture\",\r\n      \"title\": \"Architecture\",\r\n      \"readinessLabel\": \"Architecture is Ready When...\",\r\n      \"order\": 2\r\n    },\r\n    {\r\n      \"id\": \"design\",\r\n      \"title\": \"Design\",\r\n      \"readinessLabel\": \"Design is Ready When...\",\r\n      \"order\": 3\r\n    },\r\n    {\r\n      \"id\": \"delivery\",\r\n      \"title\": \"Delivery\",\r\n      \"readinessLabel\": \"Delivery is Ready When...\",\r\n      \"order\": 4\r\n    },\r\n    {\r\n      \"id\": \"publishing\",\r\n      \"title\": \"Publishing\",\r\n      \"readinessLabel\": \"Publishing is Ready When...\",\r\n      \"order\": 5\r\n    },\r\n    {\r\n      \"id\": \"improving\",\r\n      \"title\": \"Improving\",\r\n      \"readinessLabel\": \"Improving is Ready When...\",\r\n      \"order\": 6\r\n    }\r\n  ],\r\n  \"stages\": [\r\n    {\r\n      \"id\": \"strategy\",\r\n      \"title\": \"Strategy\",\r\n      \"readinessLabel\": \"Strategy is Ready When...\",\r\n      \"order\": 1,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"based-on-clear-business-needs\",\r\n          \"label\": \"API is based on clear business needs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"strategy\",\r\n          \"producedByStation\": [\r\n            \"api-product-strategy\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"business-goals-defined\",\r\n            \"market-research-done\",\r\n            \"stakeholder-approval\",\r\n            \"metrics-feedback-available\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DOMAIN-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiBusinessModelCanvas\",\r\n            \"apiValuePropositionCanvas\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"design-artifact\",\r\n            \"documentation\",\r\n            \"research\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-product-strategy/apiValuePropositionCanvas.empty.json\",\r\n            \"specs/canvases/api-product-strategy/apiBusinessModelCanvas.empty.json\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"concept-items-audited\",\r\n          \"label\": \"All concept checklist items are audited\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"aggregate\",\r\n          \"check\": {\r\n            \"type\": \"stageCoverage\",\r\n            \"stageId\": \"strategy\"\r\n          },\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"strategy\",\r\n          \"producedByStation\": [\r\n            \"api-product-strategy\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"business-goals-defined\",\r\n            \"market-research-done\",\r\n            \"stakeholder-approval\",\r\n            \"metrics-feedback-available\",\r\n            \"api-opportunity-documented\",\r\n            \"api-reusability\",\r\n            \"value-prop-validated\",\r\n            \"consumer-segments-identified\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"report\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"audit/concept-review-report.json\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"architecture\",\r\n      \"title\": \"Architecture\",\r\n      \"readinessLabel\": \"Architecture is Ready When...\",\r\n      \"order\": 2,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"versioning-decided\",\r\n          \"label\": \"Versioning strategy decided and supported by gateway\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"architecture\",\r\n          \"producedByStation\": [\r\n            \"api-platform-architecture\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-roadmap-defined\",\r\n            \"api-reusability\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-VERSION-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"contract-first-design\",\r\n            \"api-versioning-best-practices\",\r\n            \"apiops-CI-CD-for-apis\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"ci-cd\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"docs/api/architecture/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"only-via-gateway\",\r\n          \"label\": \"Only accessible via API gateway\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"architecture\",\r\n          \"producedByStation\": [\r\n            \"api-platform-architecture\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-reusability\",\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-02\",\r\n            \"REST-CAPACITY-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"businessImpactCanvas\",\r\n            \"locationsCanvas\",\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"gateway-config\",\r\n            \"infra-config\",\r\n            \"security-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/architecture/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"rate-limits-enforced\",\r\n          \"label\": \"Rate limits are enforced\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"architecture\",\r\n          \"producedByStation\": [\r\n            \"api-platform-architecture\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-roadmap-defined\",\r\n            \"api-reusability\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CAPACITY-01\",\r\n            \"REST-OBS-01\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"capacityCanvas\",\r\n            \"api-security-best-practices\",\r\n            \"scalable-infrastructure-best-practices\",\r\n            \"api-metrics-and-analytics\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"gateway-config\",\r\n            \"runtime\",\r\n            \"monitoring\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-platform-architecture/capacityCanvas.empty.json\",\r\n            \"docs/api/architecture/README.md\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"design\",\r\n      \"title\": \"Design\",\r\n      \"readinessLabel\": \"Design is Ready When...\",\r\n      \"order\": 3,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"endpoint-descriptions-present\",\r\n          \"label\": \"Endpoints have business value and feature descriptions\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"operationDescriptions\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"value-prop-validated\",\r\n            \"api-opportunity-documented\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CX-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiValuePropositionCanvas\",\r\n            \"customerJourneyCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"design-artifact\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"specs/canvases/api-product-strategy/apiValuePropositionCanvas.empty.json\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"hides-raw-backend-data\",\r\n          \"label\": \"API hides raw backend data and is designed for shared use\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"hide-backend-discrepancies\",\r\n            \"design-reflects-business-value\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DOMAIN-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"interactionCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"design-artifact\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-product-strategy/domainCanvas.empty.json\",\r\n            \"specs/canvases/api-design/interactionCanvas.empty.json\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"design-consistent\",\r\n          \"label\": \"API design is consistent with other APIs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-platform-architecture\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"architecture-patterns-validated\",\r\n            \"api-reusability\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DOMAIN-02\",\r\n            \"REST-CX-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"documentation\",\r\n            \"design-artifact\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-design/restCanvas.empty.json\",\r\n            \"docs/api/design/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"descriptive-english-naming\",\r\n          \"label\": \"Data and attribute naming uses descriptive English\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"fieldNamesDescriptive\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-NAMING-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"mandatory-fields-specified\",\r\n          \"label\": \"Mandatory fields are specified\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"requiredFieldsPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-VALIDATION-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"contract\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"dates-use-iso\",\r\n          \"label\": \"Dates use ISO format with timezone\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"dateFormatTimezone\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DATA-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"general-data-uses-standard-values\",\r\n          \"label\": \"General data uses standard values\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"standardizedEnumsOrPatterns\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"design-reflects-business-value\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DATA-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"field-names-avoid-acronyms\",\r\n          \"label\": \"Field names avoid acronyms and use full words\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"avoidAcronyms\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-NAMING-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"create-returns-identifiers\",\r\n          \"label\": \"Creating new resources returns identifiers\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is read-only and does not create resources.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-201-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"paths-max-two-resources\",\r\n          \"label\": \"Endpoint paths contain max two resources or sub-resources\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"pathDepthMax\",\r\n            \"maxDepth\": 2\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PATH-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"examples-present\",\r\n          \"label\": \"Endpoints and attributes include examples\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"examplesPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CX-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"restCanvas\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"post-for-create-update\",\r\n          \"label\": \"POST is used for create or update\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose create or update operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"design-reflects-business-value\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-POST-01\",\r\n            \"REST-HTTP-PUT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"delete-for-remove\",\r\n          \"label\": \"DELETE is used to remove resources\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose delete operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-DELETE-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"get-no-request-body\",\r\n          \"label\": \"GET has no request body and returns content\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"getNoRequestBody\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-GET-01\",\r\n            \"REST-RESP-200-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"get-empty-returns-204\",\r\n          \"label\": \"GET returns 204 if response body is empty\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"The current contract returns content for all GET operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-204-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"post-returns-200\",\r\n          \"label\": \"POST returns 200 OK when updating\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose POST updates.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-200-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"post-returns-201\",\r\n          \"label\": \"POST returns 201 Created with ID on create\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose POST creates.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-201-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"delete-returns-204\",\r\n          \"label\": \"DELETE returns 204 on success\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose DELETE operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-204-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"400-errors-specific\",\r\n          \"label\": \"400 errors provide specific error information\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"errorResponsesSpecific\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-ERROR-400-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"restCanvas\",\r\n            \"api-audit-checklist\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"401-unauthorized\",\r\n          \"label\": \"401 Unauthorized for wrong credentials\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"The current public storefront contract is intentionally unauthenticated.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-ERROR-401-01\",\r\n            \"REST-SEC-01\",\r\n            \"REST-SEC-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"security-config\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"403-forbidden\",\r\n          \"label\": \"403 Forbidden for unauthorized operations\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"The current profile is public read-only and exposes no unauthorized operations.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-ERROR-403-01\",\r\n            \"REST-SEC-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"security-config\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"spec-contains-schemas\",\r\n          \"label\": \"Spec contains request and response schema\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"schemasPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CONTRACT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"contract-first-design\",\r\n            \"restCanvas\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"contract\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"pseudo-identifiers\",\r\n          \"label\": \"UUIDs or pseudo-identifiers instead of DB IDs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"opaqueIdentifiers\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"hide-backend-discrepancies\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-07\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"contract-first-design\",\r\n            \"api-security-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"no-sensitive-data-in-urls\",\r\n          \"label\": \"No sensitive data in URLs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"noSensitiveDataInPaths\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"hide-backend-discrepancies\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-06\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"contract-first-design\",\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"http-methods-match-resources\",\r\n          \"label\": \"HTTP methods only for intended resources\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"methodResourceConsistency\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-GET-01\",\r\n            \"REST-HTTP-POST-01\",\r\n            \"REST-HTTP-PUT-01\",\r\n            \"REST-HTTP-DELETE-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"delivery\",\r\n      \"title\": \"Delivery\",\r\n      \"readinessLabel\": \"Delivery is Ready When...\",\r\n      \"order\": 4,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"design-items-audited\",\r\n          \"label\": \"All prototype and design items are audited\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"aggregate\",\r\n          \"check\": {\r\n            \"type\": \"stageCoverage\",\r\n            \"stageId\": \"design\"\r\n          },\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"design-reflects-business-value\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"report\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"audit/production-readiness-review.json\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"spec-validated-on-change\",\r\n          \"label\": \"Spec validated on every change\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"validationWorkflowPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-audit-checklist\",\r\n            \"contract-first-design\",\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"api-testing-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"ci-cd\",\r\n            \"spec\",\r\n            \"test\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \".github/workflows/openapi-lint.yml\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"schema-and-examples-pass\",\r\n          \"label\": \"Schema and examples pass validation\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"examplesPassValidation\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"architecture-patterns-validated\",\r\n            \"api-contract-tested\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-01\",\r\n            \"REST-CONTRACT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"contract-first-design\",\r\n            \"api-audit-checklist\",\r\n            \"api-testing-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"test\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"uses-https\",\r\n          \"label\": \"Uses HTTPS or encrypted protocols\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-05\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"auth-protection\",\r\n          \"label\": \"Endpoints protected by authentication\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is intentionally public read-only.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-01\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"gateway-config\",\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"token-auth\",\r\n          \"label\": \"Token-based authentication\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is intentionally public read-only.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"csrf-protection\",\r\n          \"label\": \"Protected against CSRF\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is intentionally public read-only.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-08\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-development-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"code\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"inputs-auto-validated\",\r\n          \"label\": \"Inputs auto-validated by framework\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-VALIDATION-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-development-best-practices\",\r\n            \"contract-first-design\",\r\n            \"api-testing-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"code\",\r\n            \"test\",\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"docs/api/delivery/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"outputs-auto-escaped\",\r\n          \"label\": \"Outputs auto-escaped by framework\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"JSON APIs do not typically require output escaping in the same way as HTML rendering.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-development-best-practices\",\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"code\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"encryption-in-transit\",\r\n          \"label\": \"Encryption for data in transit and storage\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-05\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\",\r\n            \"api-metrics-and-analytics\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"infra-config\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"message-integrity\",\r\n          \"label\": \"Message integrity implemented\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-OBS-01\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"api-compliance-best-practices\",\r\n            \"api-metrics-and-analytics\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"monitoring\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/architecture/README.md\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"publishing\",\r\n      \"title\": \"Publishing\",\r\n      \"readinessLabel\": \"Publishing is Ready When...\",\r\n      \"order\": 5,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"published-via-api-management\",\r\n          \"label\": \"Published via API management\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"api-onboarding-best-practices\",\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"gateway-config\",\r\n            \"ci-cd\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \".github/workflows/openapi-lint.yml\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"visible-in-dev-portal\",\r\n          \"label\": \"Visible in developer portal\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-documentation-ready\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"api-community-engagement-strategies\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"documentation\",\r\n            \"runtime\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"docs-auto-generated\",\r\n          \"label\": \"Docs auto-generated from spec and schema\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\",\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-documentation-ready\",\r\n            \"api-ready-for-publishing\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CONTRACT-02\",\r\n            \"REST-PUBLISH-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"contract-first-design\",\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"api-onboarding-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"documentation\",\r\n            \"ci-cd\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"docs/api/audit/design-audit.read-only.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"spec-auto-updated\",\r\n          \"label\": \"Spec auto-updated to gateway and dev portal\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\",\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CONTRACT-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"contract-first-design\",\r\n            \"api-onboarding-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"ci-cd\",\r\n            \"gateway-config\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \".github/workflows/openapi-lint.yml\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"official-domain\",\r\n          \"label\": \"Published under official organization domain\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"documentation\",\r\n            \"runtime\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"improving\",\r\n      \"title\": \"Improving\",\r\n      \"readinessLabel\": \"Improving is Ready When...\",\r\n      \"order\": 6,\r\n      \"items\": []\r\n    }\r\n  ],\r\n  \"guidelines\": [\r\n    {\r\n      \"id\": \"REST-CONTRACT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST implement endpoints, parameters, request bodies, response bodies, and error responses as defined in the validated OpenAPI contract.\",\r\n      \"relatedAuditItems\": [\r\n        \"spec-contains-schemas\",\r\n        \"schema-and-examples-pass\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CONTRACT-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST keep the implementation, published OpenAPI description, gateway configuration, and developer portal documentation aligned on every change.\",\r\n      \"relatedAuditItems\": [\r\n        \"docs-auto-generated\",\r\n        \"spec-auto-updated\",\r\n        \"spec-validated-on-change\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-VALIDATION-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST validate path parameters, query parameters, headers, and JSON request bodies against the OpenAPI schema before business processing.\",\r\n      \"relatedAuditItems\": [\r\n        \"mandatory-fields-specified\",\r\n        \"400-errors-specific\",\r\n        \"inputs-auto-validated\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DOMAIN-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST expose business-oriented resources and attributes rather than raw backend tables, internal service payloads, or system-specific field names.\",\r\n      \"relatedAuditItems\": [\r\n        \"based-on-clear-business-needs\",\r\n        \"hides-raw-backend-data\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DOMAIN-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST preserve validated meanings of entities, attributes, statuses, and source-of-truth rules across all endpoints and operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"design-consistent\",\r\n        \"general-data-uses-standard-values\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-NAMING-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST use descriptive English names for resources and attributes.\",\r\n      \"relatedAuditItems\": [\r\n        \"descriptive-english-naming\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-NAMING-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST avoid unexplained acronyms in public field and resource names.\",\r\n      \"relatedAuditItems\": [\r\n        \"field-names-avoid-acronyms\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DATA-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST use ISO date-time values with timezone information where dates are exposed.\",\r\n      \"relatedAuditItems\": [\r\n        \"dates-use-iso\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DATA-02\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API SHOULD use standard codes, controlled vocabularies, and standardized value sets where applicable.\",\r\n      \"relatedAuditItems\": [\r\n        \"general-data-uses-standard-values\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API MUST describe the business value and feature intent of each endpoint or capability.\",\r\n      \"relatedAuditItems\": [\r\n        \"endpoint-descriptions-present\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API MUST include examples for endpoints, request bodies, response bodies, and key attributes.\",\r\n      \"relatedAuditItems\": [\r\n        \"examples-present\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-03\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API SHOULD use consistent pagination, filtering, sorting, and response conventions across resources.\",\r\n      \"relatedAuditItems\": [\r\n        \"design-consistent\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-GET-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use GET for safe read-only operations and MUST NOT define a request body for GET operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-no-request-body\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-POST-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use POST for resource creation and other non-idempotent operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"post-for-create-update\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-PUT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use PUT only for full resource replacement.\",\r\n      \"relatedAuditItems\": [\r\n        \"post-for-create-update\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-DELETE-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use DELETE to remove resources.\",\r\n      \"relatedAuditItems\": [\r\n        \"delete-for-remove\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PATH-01\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"resource-modeling\",\r\n      \"requirement\": \"The REST API SHOULD keep endpoint paths shallow and avoid more than two resource or sub-resource levels unless explicitly justified.\",\r\n      \"relatedAuditItems\": [\r\n        \"paths-max-two-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-200-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 200 OK for successful reads and updates that include a response body.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-no-request-body\",\r\n        \"post-returns-200\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-201-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 201 Created and the created resource identifier when a new resource is created.\",\r\n      \"relatedAuditItems\": [\r\n        \"create-returns-identifiers\",\r\n        \"post-returns-201\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-204-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 204 No Content for successful delete operations that do not return a body.\",\r\n      \"relatedAuditItems\": [\r\n        \"delete-returns-204\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-204-02\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API SHOULD return 204 No Content for successful operations that intentionally return no response body.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-empty-returns-204\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-400-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST define 400 Bad Request responses with specific and actionable validation error information.\",\r\n      \"relatedAuditItems\": [\r\n        \"400-errors-specific\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-401-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST return 401 Unauthorized for missing or invalid credentials.\",\r\n      \"relatedAuditItems\": [\r\n        \"401-unauthorized\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-403-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST return 403 Forbidden for authenticated clients lacking sufficient permission.\",\r\n      \"relatedAuditItems\": [\r\n        \"403-forbidden\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-VERSION-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"versioning\",\r\n      \"requirement\": \"The REST API MUST define a versioning strategy before production release, and the strategy MUST be supportable by the API gateway.\",\r\n      \"relatedAuditItems\": [\r\n        \"versioning-decided\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST require authentication for protected endpoints.\",\r\n      \"relatedAuditItems\": [\r\n        \"auth-protection\",\r\n        \"401-unauthorized\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST use token-based authentication or another approved modern authentication mechanism for protected endpoints.\",\r\n      \"relatedAuditItems\": [\r\n        \"token-auth\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-03\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST enforce object-level and function-level authorization on every protected operation.\",\r\n      \"relatedAuditItems\": [\r\n        \"401-unauthorized\",\r\n        \"403-forbidden\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-04\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST mitigate OWASP API risks including broken object level authorization, broken function level authorization, injection, and unrestricted resource consumption.\",\r\n      \"relatedAuditItems\": [\r\n        \"auth-protection\",\r\n        \"rate-limits-enforced\",\r\n        \"no-sensitive-data-in-urls\",\r\n        \"message-integrity\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-05\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST use HTTPS or another approved encrypted protocol for all traffic.\",\r\n      \"relatedAuditItems\": [\r\n        \"uses-https\",\r\n        \"encryption-in-transit\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-06\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST NOT expose sensitive information in URLs, query strings, logs, or unnecessary response fields.\",\r\n      \"relatedAuditItems\": [\r\n        \"no-sensitive-data-in-urls\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-07\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API SHOULD use UUIDs or other non-sequential public identifiers where direct database identifiers would increase exposure risk.\",\r\n      \"relatedAuditItems\": [\r\n        \"pseudo-identifiers\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-08\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST implement CSRF protection where relevant to the authentication model and client interaction pattern.\",\r\n      \"relatedAuditItems\": [\r\n        \"csrf-protection\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CAPACITY-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"resilience-capacity\",\r\n      \"requirement\": \"The REST API MUST define and enforce rate limits, throttling, or quotas according to capacity expectations.\",\r\n      \"relatedAuditItems\": [\r\n        \"rate-limits-enforced\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CAPACITY-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"resilience-capacity\",\r\n      \"requirement\": \"The REST API MUST implement resilience controls such as timeouts, fallback behavior, and degradation handling according to business impact.\",\r\n      \"relatedAuditItems\": [\r\n        \"only-via-gateway\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-OBS-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"observability\",\r\n      \"requirement\": \"The REST API MUST implement logs, metrics, and monitoring needed to observe validation failures, auth failures, traffic, latency, and dependency health.\",\r\n      \"relatedAuditItems\": [\r\n        \"rate-limits-enforced\",\r\n        \"message-integrity\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be published through an API management platform.\",\r\n      \"relatedAuditItems\": [\r\n        \"published-via-api-management\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be accessible only through approved API gateway paths and managed entry points.\",\r\n      \"relatedAuditItems\": [\r\n        \"only-via-gateway\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-03\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API SHOULD be visible in a developer portal with documentation generated from the contract.\",\r\n      \"relatedAuditItems\": [\r\n        \"visible-in-dev-portal\",\r\n        \"docs-auto-generated\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-04\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be published under an approved organizational domain.\",\r\n      \"relatedAuditItems\": [\r\n        \"official-domain\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-AUDIT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST validate the specification, schema, and examples on every change.\",\r\n      \"relatedAuditItems\": [\r\n        \"spec-validated-on-change\",\r\n        \"schema-and-examples-pass\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-AUDIT-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST pass concept, design, security, and production-readiness checks before release.\",\r\n      \"relatedAuditItems\": [\r\n        \"concept-items-audited\",\r\n        \"design-items-audited\"\r\n      ]\r\n    }\r\n  ]\r\n}\r\n",
              "draft": false
            },
            {
              "id": "api-compliance-best-practices",
              "slug": "resources/api-compliance-best-practices",
              "title": "API Compliance Best Practices",
              "description": "Ensure APIs meet legal, regulatory, and internal compliance through documentation, controls, and automated validations.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 104,
              "outcomes": [
                "Shared understanding of the purpose and use of API Compliance Best Practices",
                "A consistent approach to applying API Compliance Best Practices",
                "Improved application of the related practices"
              ],
              "steps": [
                "Document compliance measures and ensure they are communicated to stakeholders and consumers.",
                "Implement measures to ensure APIs comply with these requirements, including data encryption, access controls, and audit trails.",
                "Use checklists, linters, and testing tools to verify consistency and conformance with standards."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "businessImpactCanvas",
              "slug": "resources/business-impact-canvas",
              "title": "Business Impact Canvas",
              "description": "Identify business, availability, security, data, compliance, and operational risks that should shape architecture and platform decisions.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 4,
              "outcomes": [
                "Documented business and operational impact assessment",
                "Prioritized risks and mitigation actions",
                "Evidence for architecture and platform decisions"
              ],
              "steps": [
                "Availability Risks: Identify risks and impacts.",
                "Ways to Mitigate Availability Risks: Define mitigation measures.",
                "Security Risks: Document security-related risks.",
                "Ways to Mitigate Security Risks: Propose strategies to mitigate security risks.",
                "Data Risks: Identify risks to data accuracy or availability.",
                "Ways to Mitigate Data Risks: Plan strategies to address data risks."
              ],
              "canvasId": "businessImpactCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "locationsCanvas",
              "slug": "resources/location-canvas",
              "title": "Location Canvas",
              "description": "Map consumer, producer, system, data, network, regulatory, and trust-boundary locations to ensure compliance and performance across regions.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 6,
              "outcomes": [
                "Documented location, residency, network, and regulatory requirements",
                "Regional performance and accessibility constraints identified",
                "Data residency, trust boundaries, and applicable regulations clarified"
              ],
              "steps": [
                "Map locations of producers, source systems, platforms, and consumers.",
                "Document where consumers are located.",
                "Identify applicable regulations.",
                "Document where data must reside.",
                "Ensure the capability is accessible in all intended network regions.",
                "Validate network performance across regions."
              ],
              "canvasId": "locationsCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capacityCanvas",
              "slug": "resources/capacity-canvas",
              "title": "Capacity Canvas",
              "description": "Plan capacity for current and future demand, including volumes, peaks, latency, availability, scaling, caching, and rate limits for the selected capability and implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 7,
              "outcomes": [
                "Capacity requirements aligned with expected business demand",
                "Peak-load, availability, and growth assumptions documented",
                "Scaling, caching, and rate-limiting decisions defined"
              ],
              "steps": [
                "Document current business volumes",
                "Forecast future consumption trends",
                "Plan for peak load and availability requirements",
                "Define caching and rate-limiting strategies",
                "Propose scaling strategies"
              ],
              "canvasId": "capacityCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "domainCanvas",
              "slug": "resources/domain-canvas",
              "title": "Domain Canvas",
              "description": "A modeling tool to define and communicate the key entities and relationships in your domain, ensuring semantic consistency across capabilities, integrations, APIs, data products, and services.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 152,
              "outcomes": [
                "Shared domain model and terminology",
                "Core entities, relationships, rules, and ownership clarified",
                "Semantic consistency across capabilities, integrations, APIs, data products, and services"
              ],
              "steps": [
                "Define core entities, their attributes, and relationships to create a shared conceptual understanding across capabilities, integrations, APIs, data products, and services."
              ],
              "canvasId": "domainCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "interactionCanvas",
              "slug": "resources/interaction-canvas",
              "title": "Interaction Canvas",
              "description": "Define interactions, workflows, inputs, outputs, commands, queries, events, and expected responses to ensure a consistent consumer experience.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 9,
              "outcomes": [
                "Defined interaction model for the selected capability",
                "Inputs, outputs, commands, queries, events, and responses clarified",
                "Validation rules and interaction expectations agreed"
              ],
              "steps": [
                "Map interactions to user, consumer, or system tasks",
                "Define access points, operations, commands, queries, or events for each interaction",
                "Document inputs and outputs for each interaction.",
                "Specify validation rules and constraints",
                "Create interaction models for CRUD, query-driven, command-driven, and event-driven interactions"
              ],
              "canvasId": "interactionCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            }
          ],
          "promptIds": [
            "api-engineer:facilitate-station",
            "api-engineer:use-resources",
            "api-engineer:next-actions"
          ]
        },
        {
          "id": "api-devrel-specialist",
          "stakeholderId": "api-devrel-specialist",
          "title": "Documentation and DevRel Owner",
          "summary": "Owns onboarding content, developer communication, and documentation quality for API consumers.",
          "stakeholder": {
            "id": "api-devrel-specialist",
            "sourceKey": "api-devrel-specialist",
            "sourceStakeholderId": "api-devrel-specialist",
            "title": "Documentation and DevRel Owner",
            "description": "Owns onboarding content, developer communication, and documentation quality for API consumers.",
            "involvement": ""
          },
          "cycles": [
            {
              "id": "capability-productization-cycle",
              "title": "Capability Productization Cycle",
              "description": "A cycle for turning business capabilities into reusable digital capabilities before selecting the implementation style."
            },
            {
              "id": "api-productization-cycle",
              "title": "API Productization Cycle",
              "description": "The API-focused APIOps Cycles journey for productizing, designing, delivering, publishing, and improving APIs."
            },
            {
              "id": "integration-productization-cycle",
              "title": "Integration Productization Cycle",
              "description": "A cycle for productizing reusable integration capabilities before selecting the implementation style."
            },
            {
              "id": "automation-cycle",
              "title": "Automation Cycle",
              "description": "A cycle for identifying, designing, delivering, enabling, and improving automation opportunities."
            }
          ],
          "stations": [
            {
              "id": "api-consumer-experience",
              "title": "Consumer Requirements & Onboarding",
              "description": "Capture consumer onboarding, standards, non-functional requirements, service expectations, constraints, security needs, allowed protocols, data freshness, SLAs, observability, recovery, adoption requirements, and producer responsibilities."
            },
            {
              "id": "api-publishing",
              "title": "Publishing & Enablement",
              "description": "Publish reusable capability information so consumers can discover, request, onboard, use, and get support."
            },
            {
              "id": "monitoring-and-improving",
              "title": "Monitoring & Improvement",
              "description": "Monitor usage, reliability, data quality, consumer outcomes, operational cost, and reuse opportunities after release."
            },
            {
              "id": "api-design",
              "title": "Solution & Interface Design",
              "description": "Design the interface contract and interaction model after the architecture choice is justified."
            }
          ],
          "canvases": [
            {
              "id": "consumerExperienceRequirementsCanvas",
              "title": "Consumer Experience Requirements Canvas"
            },
            {
              "id": "domainCanvas",
              "title": "Domain Canvas"
            },
            {
              "id": "interactionCanvas",
              "title": "Interaction Canvas"
            },
            {
              "id": "apiValuePropositionCanvas",
              "title": "API Value Proposition Canvas"
            },
            {
              "id": "customerJourneyCanvas",
              "title": "Customer Journey Canvas"
            },
            {
              "id": "restCanvas",
              "title": "REST Canvas"
            },
            {
              "id": "eventCanvas",
              "title": "Event Canvas"
            },
            {
              "id": "graphqlCanvas",
              "title": "GraphQL Canvas"
            }
          ],
          "decisions": [
            "Use the Consumer Experience Requirements Canvas to capture consumer goals, availability, freshness, volume, performance, data quality, security, onboarding, change, observability, and recovery expectations.",
            "Use onboarding guidance to describe how consumers will find, request, test, get approved for, and start using the capability.",
            "Use the resulting journey and requirements to improve onboarding, documentation, support, and feedback loops for capability consumers.",
            "Use consumer experience and onboarding guidance to make expectations explicit for both consumers and producers.",
            "The right architecture depends on consumer goals, onboarding expectations, service levels, data quality needs, change tolerance, observability, support, and producer constraints.",
            "Publish capability information to the appropriate catalogs, portals, gateways, or environments to support reuse by multiple consumers."
          ],
          "outputs": [
            "Documented consumer requirements and onboarding expectations",
            "Clear producer responsibilities and support expectations",
            "Architecture-relevant constraints ready for decision making",
            "Improved adoption through consumer empathy, standards, and producer clarity",
            "design-artifact",
            "documentation",
            "consumer-feedback",
            "A discoverable reusable capability"
          ],
          "recommendedResources": [
            {
              "id": "consumerExperienceRequirementsCanvas",
              "slug": "resources/consumer-experience-requirements-canvas",
              "title": "Consumer Experience Requirements Canvas",
              "description": "A requirements canvas for consumer experience and non-functional needs that should guide the later architecture and implementation-style decision.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 3.2,
              "outcomes": [
                "Technology-agnostic consumer and service requirements",
                "Experience and non-functional needs captured before design starts",
                "Architecture implications documented for implementation-style selection"
              ],
              "steps": [
                "Capture consumer goals and usage context.",
                "Document availability, timeliness, volume, performance, data quality, and consistency expectations.",
                "Document security, privacy, onboarding, change, observability, support, and recovery expectations.",
                "Summarize what the requirements imply for possible implementation styles."
              ],
              "canvasId": "consumerExperienceRequirementsCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "api-onboarding-best-practices",
              "slug": "resources/api-onboarding-best-practices",
              "title": "API Onboarding Best Practices",
              "description": "Best practices to streamline API consumer onboarding journeys with step-by-step registration, discovery, and first-call guidance.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 121,
              "outcomes": [
                "Shared understanding of the purpose and use of API Onboarding Best Practices",
                "A consistent approach to applying API Onboarding Best Practices",
                "Improved application of the related practices"
              ],
              "steps": [
                "Define the API consumer journey from discovery to troubleshooting, identifying key touchpoints and pain points.",
                "Develop onboarding processes and resources to help API consumers understand how to use APIs effectively.",
                "Document how consumers find and use the API, including onboarding processes and registration."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "service-agreement-template",
              "slug": "resources/service-agreement-template",
              "title": "Service Agreement Template",
              "description": "A customizable agreement format that defines expectations, SLAs, responsibilities, and access terms for API consumption.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 172,
              "outcomes": [
                "Shared understanding of the purpose and use of Service Agreement Template",
                "A consistent approach to applying Service Agreement Template",
                "Improved application of the related practices"
              ],
              "steps": [
                "Define service agreements that outline the expectations, service levels, and responsibilities for each API.",
                "Use standardized formats to create machine-readable service agreements that are easy to share and validate.",
                "Ensure service agreements are reviewed and approved by stakeholders to ensure alignment and clarity."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "api-metrics-and-analytics",
              "slug": "resources/api-metrics-and-analytics",
              "title": "API Metrics And Analytics",
              "description": "A resource for defining, collecting, and analyzing API performance and usage data to align technical KPIs with business outcomes.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 119,
              "outcomes": [
                "Shared understanding of the purpose and use of API Metrics And Analytics",
                "A consistent approach to applying API Metrics And Analytics",
                "Improved application of the related practices"
              ],
              "steps": [
                "Identify key performance indicators (KPIs) to measure API success against business goals.",
                "Define and monitor performance metrics (e.g., API calls, latency, error rates) and adoption metrics (e.g., NPS).",
                "Monitor API initiatives to ensure adherence to operating guidelines and governance practices"
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "api-community-engagement-strategies",
              "slug": "resources/api-community-engagement-strategies",
              "title": "API Community Engagement Strategies",
              "description": "A playbook for fostering API adoption by cultivating communities through content, support channels, feedback loops, and social engagement strategies.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 103,
              "outcomes": [
                "Shared understanding of the purpose and use of API Community Engagement Strategies",
                "A consistent approach to applying API Community Engagement Strategies",
                "Improved application of the related practices"
              ],
              "steps": [
                "Develop marketing strategies to promote APIs to target audiences, including social media, blogs, and webinars.",
                "Create promotional materials (e.g., case studies, success stories) that highlight the value and benefits of APIs.",
                "Create educational materials (e.g., tutorials, documentation) that explain API features, benefits, and usage patterns.",
                "Engage with API consumers through feedback loops, support channels, and community forums to understand their needs and improve API adoption.",
                "Analyze API usage metrics and incorporate user feedback into API iterations."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "domainCanvas",
              "slug": "resources/domain-canvas",
              "title": "Domain Canvas",
              "description": "A modeling tool to define and communicate the key entities and relationships in your domain, ensuring semantic consistency across capabilities, integrations, APIs, data products, and services.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 152,
              "outcomes": [
                "Shared domain model and terminology",
                "Core entities, relationships, rules, and ownership clarified",
                "Semantic consistency across capabilities, integrations, APIs, data products, and services"
              ],
              "steps": [
                "Define core entities, their attributes, and relationships to create a shared conceptual understanding across capabilities, integrations, APIs, data products, and services."
              ],
              "canvasId": "domainCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "interactionCanvas",
              "slug": "resources/interaction-canvas",
              "title": "Interaction Canvas",
              "description": "Define interactions, workflows, inputs, outputs, commands, queries, events, and expected responses to ensure a consistent consumer experience.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 9,
              "outcomes": [
                "Defined interaction model for the selected capability",
                "Inputs, outputs, commands, queries, events, and responses clarified",
                "Validation rules and interaction expectations agreed"
              ],
              "steps": [
                "Map interactions to user, consumer, or system tasks",
                "Define access points, operations, commands, queries, or events for each interaction",
                "Document inputs and outputs for each interaction.",
                "Specify validation rules and constraints",
                "Create interaction models for CRUD, query-driven, command-driven, and event-driven interactions"
              ],
              "canvasId": "interactionCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "contract-first-design",
              "slug": "resources/contract-first-design",
              "title": "Contract First Design",
              "description": "A guideline advocating for API-first approaches using formal contracts (e.g., OpenAPI) to align stakeholders before development.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 146,
              "outcomes": [
                "Shared understanding of the purpose and use of Contract First Design",
                "A consistent approach to applying Contract First Design",
                "Improved application of the related practices"
              ],
              "steps": [
                "Apply contract-first or design-first approaches to ensure API interface contracts are validated before implementation.",
                "Define API interface contracts that outline the expectations, responsibilities, and usage guidelines for each API.",
                "Use standardized formats (e.g., OpenAPI, AsyncAPI) to create machine-readable API interface contracts that are easy to share and validate."
              ],
              "canvasId": null,
              "sourcePath": "src/snippets/api-contract-example.yaml",
              "sourceUrl": null,
              "contentMarkdown": "openapi: 3.0.3\r\ninfo:\r\n  title: Sample Catalog API\r\n  version: 1.0.0\r\n  description: |\r\n    Starter example for a read-only APIOps Cycles API.\r\n    This example keeps the contract audit-friendly and easy to extend.\r\nservers:\r\n  - url: /v1\r\n    description: Versioned API base path\r\ntags:\r\n  - name: catalog\r\n    description: Browse and search catalog items\r\npaths:\r\n  /items:\r\n    get:\r\n      tags: [catalog]\r\n      summary: List catalog items\r\n      description: Returns a paginated list of public catalog items.\r\n      operationId: listItems\r\n      parameters:\r\n        - $ref: \"#/components/parameters/searchTerm\"\r\n        - $ref: \"#/components/parameters/categoryId\"\r\n        - $ref: \"#/components/parameters/page\"\r\n        - $ref: \"#/components/parameters/pageSize\"\r\n      responses:\r\n        \"200\":\r\n          description: Item list\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemListResponse\"\r\n              examples:\r\n                default:\r\n                  value:\r\n                    data:\r\n                      - itemId: item-123\r\n                        slug: blue-widget\r\n                        name: Blue Widget\r\n                        status: published\r\n                    page:\r\n                      number: 1\r\n                      size: 20\r\n                      totalItems: 1\r\n        \"400\":\r\n          $ref: \"#/components/responses/BadRequest\"\r\n        \"429\":\r\n          $ref: \"#/components/responses/TooManyRequests\"\r\n  /items/{itemId}:\r\n    get:\r\n      tags: [catalog]\r\n      summary: Get item by id\r\n      description: Returns a single public catalog item by opaque identifier.\r\n      operationId: getItemById\r\n      parameters:\r\n        - $ref: \"#/components/parameters/itemId\"\r\n      responses:\r\n        \"200\":\r\n          description: Item details\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemDetail\"\r\n        \"400\":\r\n          $ref: \"#/components/responses/BadRequest\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\n  /items/by-slug/{slug}:\r\n    get:\r\n      tags: [catalog]\r\n      summary: Get item by slug\r\n      description: Returns a single item by public slug.\r\n      operationId: getItemBySlug\r\n      parameters:\r\n        - $ref: \"#/components/parameters/slug\"\r\n      responses:\r\n        \"200\":\r\n          description: Item details\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemDetail\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\n  /categories/{categoryId}/items:\r\n    get:\r\n      tags: [catalog]\r\n      summary: List items in category\r\n      description: Returns public items in a category.\r\n      operationId: listItemsByCategory\r\n      parameters:\r\n        - $ref: \"#/components/parameters/categoryId\"\r\n      responses:\r\n        \"200\":\r\n          description: Category item list\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemListResponse\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\ncomponents:\r\n  parameters:\r\n    itemId:\r\n      name: itemId\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9][a-z0-9-]{1,63}$\"\r\n      example: item-123\r\n    slug:\r\n      name: slug\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9]+(?:-[a-z0-9]+)*$\"\r\n      example: blue-widget\r\n    categoryId:\r\n      name: categoryId\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9][a-z0-9-]{1,63}$\"\r\n      example: home-goods\r\n    searchTerm:\r\n      name: searchTerm\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: string\r\n        minLength: 1\r\n      example: widget\r\n    page:\r\n      name: page\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: integer\r\n        minimum: 1\r\n        default: 1\r\n    pageSize:\r\n      name: pageSize\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: integer\r\n        minimum: 1\r\n        maximum: 100\r\n        default: 20\r\n  responses:\r\n    BadRequest:\r\n      description: Validation failed\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n          examples:\r\n            default:\r\n              value:\r\n                code: BAD_REQUEST\r\n                message: Invalid request\r\n    NotFound:\r\n      description: Resource not found\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n    TooManyRequests:\r\n      description: Rate limit exceeded\r\n      headers:\r\n        Retry-After:\r\n          schema:\r\n            type: integer\r\n          description: Seconds until the next allowed request.\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n  schemas:\r\n    ItemListResponse:\r\n      type: object\r\n      required: [data, page]\r\n      properties:\r\n        data:\r\n          type: array\r\n          items:\r\n            $ref: \"#/components/schemas/ItemSummary\"\r\n        page:\r\n          $ref: \"#/components/schemas/Page\"\r\n    ItemSummary:\r\n      type: object\r\n      required: [itemId, slug, name, status]\r\n      properties:\r\n        itemId:\r\n          type: string\r\n        slug:\r\n          type: string\r\n        name:\r\n          type: string\r\n        status:\r\n          type: string\r\n          enum: [published, hidden]\r\n    ItemDetail:\r\n      allOf:\r\n        - $ref: \"#/components/schemas/ItemSummary\"\r\n        - type: object\r\n          properties:\r\n            description:\r\n              type: string\r\n            categories:\r\n              type: array\r\n              items:\r\n                type: string\r\n            variants:\r\n              type: array\r\n              items:\r\n                $ref: \"#/components/schemas/Variant\"\r\n    Variant:\r\n      type: object\r\n      required: [variantId, sku, price, inventory]\r\n      properties:\r\n        variantId:\r\n          type: string\r\n        sku:\r\n          type: string\r\n        price:\r\n          $ref: \"#/components/schemas/Price\"\r\n        inventory:\r\n          $ref: \"#/components/schemas/Inventory\"\r\n    Price:\r\n      type: object\r\n      required: [amount, currency]\r\n      properties:\r\n        amount:\r\n          type: number\r\n          format: decimal\r\n        currency:\r\n          type: string\r\n          example: EUR\r\n    Inventory:\r\n      type: object\r\n      required: [available]\r\n      properties:\r\n        available:\r\n          type: integer\r\n          minimum: 0\r\n        reserved:\r\n          type: integer\r\n          minimum: 0\r\n        source:\r\n          type: string\r\n    Page:\r\n      type: object\r\n      required: [number, size, totalItems]\r\n      properties:\r\n        number:\r\n          type: integer\r\n        size:\r\n          type: integer\r\n        totalItems:\r\n          type: integer\r\n    ErrorResponse:\r\n      type: object\r\n      required: [code, message]\r\n      properties:\r\n        code:\r\n          type: string\r\n        message:\r\n          type: string\r\n",
              "draft": true
            },
            {
              "id": "apiValuePropositionCanvas",
              "slug": "resources/api-value-proposition-canvas",
              "title": "API Value Proposition Canvas",
              "description": "Align API features with user needs by mapping tasks, pains, and gains to API products.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 2,
              "outcomes": [
                "Focused feature development",
                "Alignment with user needs",
                "Improved API consumer satisfaction"
              ],
              "steps": [
                "List user journey tasks",
                "Identify features delivering expected gains",
                "Define features addressing challenges",
                "Map features to API products"
              ],
              "canvasId": "apiValuePropositionCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "customerJourneyCanvas",
              "slug": "resources/customer-journey-canvas",
              "title": "Customer Journey Canvas",
              "description": "Map customer, partner, or consumer journeys to identify needs, pain points, gains, inputs, outputs, and experience expectations.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 1,
              "outcomes": [
                "Shared understanding of the customer, partner, or consumer journey",
                "Needs, pain points, gains, inputs, and outputs documented",
                "Journey evidence available for capability, requirements, and architecture decisions"
              ],
              "steps": [
                "Define customer persona",
                "Identify triggers for the journey",
                "Describe the journey's end",
                "Map journey steps with inputs/outputs",
                "Identify customer pains",
                "Summarize customer gains",
                "Define necessary inputs and resulting outputs",
                "Define interactions and processing expectations for each step"
              ],
              "canvasId": "customerJourneyCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            }
          ],
          "promptIds": [
            "api-devrel-specialist:facilitate-station",
            "api-devrel-specialist:use-resources",
            "api-devrel-specialist:next-actions"
          ]
        },
        {
          "id": "domain-specialist",
          "stakeholderId": "domain-specialist",
          "title": "Domain Expert",
          "summary": "Brings deep knowledge of the business domain, concepts, rules, and constraints the capability or interface must reflect.",
          "stakeholder": {
            "id": "domain-specialist",
            "sourceKey": "domain-specialist",
            "sourceStakeholderId": "domain-specialist",
            "title": "Domain Expert",
            "description": "Brings deep knowledge of the business domain, concepts, rules, and constraints the capability or interface must reflect.",
            "involvement": ""
          },
          "cycles": [
            {
              "id": "capability-productization-cycle",
              "title": "Capability Productization Cycle",
              "description": "A cycle for turning business capabilities into reusable digital capabilities before selecting the implementation style."
            },
            {
              "id": "api-productization-cycle",
              "title": "API Productization Cycle",
              "description": "The API-focused APIOps Cycles journey for productizing, designing, delivering, publishing, and improving APIs."
            },
            {
              "id": "integration-productization-cycle",
              "title": "Integration Productization Cycle",
              "description": "A cycle for productizing reusable integration capabilities before selecting the implementation style."
            },
            {
              "id": "automation-cycle",
              "title": "Automation Cycle",
              "description": "A cycle for identifying, designing, delivering, enabling, and improving automation opportunities."
            }
          ],
          "stations": [
            {
              "id": "api-product-strategy",
              "title": "Strategy",
              "description": "Frame the business need as a reusable capability before choosing the implementation style."
            },
            {
              "id": "api-consumer-experience",
              "title": "Consumer Requirements & Onboarding",
              "description": "Capture consumer onboarding, standards, non-functional requirements, service expectations, constraints, security needs, allowed protocols, data freshness, SLAs, observability, recovery, adoption requirements, and producer responsibilities."
            },
            {
              "id": "api-design",
              "title": "Solution & Interface Design",
              "description": "Design the interface contract and interaction model after the architecture choice is justified."
            },
            {
              "id": "api-platform-architecture",
              "title": "Architecture & Platform Decisions",
              "description": "Use requirements and constraints to decide the right architecture pattern and enabling platform capabilities."
            },
            {
              "id": "monitoring-and-improving",
              "title": "Monitoring & Improvement",
              "description": "Monitor usage, reliability, data quality, consumer outcomes, operational cost, and reuse opportunities after release."
            }
          ],
          "canvases": [
            {
              "id": "customerJourneyCanvas",
              "title": "Customer Journey Canvas"
            },
            {
              "id": "domainCanvas",
              "title": "Domain Canvas"
            },
            {
              "id": "capabilityValuePropositionCanvas",
              "title": "Capability Value Proposition Canvas"
            },
            {
              "id": "capabilityBusinessModelCanvas",
              "title": "Capability Business Model Canvas"
            },
            {
              "id": "consumerExperienceRequirementsCanvas",
              "title": "Consumer Experience Requirements Canvas"
            },
            {
              "id": "interactionCanvas",
              "title": "Interaction Canvas"
            },
            {
              "id": "businessImpactCanvas",
              "title": "Business Impact Canvas"
            },
            {
              "id": "locationsCanvas",
              "title": "Locations Canvas"
            },
            {
              "id": "capacityCanvas",
              "title": "Capacity Canvas"
            },
            {
              "id": "apiValuePropositionCanvas",
              "title": "API Value Proposition Canvas"
            },
            {
              "id": "apiBusinessModelCanvas",
              "title": "API Business Model Canvas"
            },
            {
              "id": "restCanvas",
              "title": "REST Canvas"
            },
            {
              "id": "eventCanvas",
              "title": "Event Canvas"
            },
            {
              "id": "graphqlCanvas",
              "title": "GraphQL Canvas"
            }
          ],
          "decisions": [
            "Map the customer or partner journey that creates the capability need and reveals tasks, pains, gains, inputs, outputs, and decision points.",
            "Define the core entities, attributes, relationships, ownership, and business rules that the capability must respect.",
            "Use the Capability Value Proposition Canvas to capture consumer tasks, gains, pains, and reusable capability features without naming the delivery technology too early.",
            "Use the Capability Business Model Canvas to clarify ownership, partners, channels, costs, benefits, support, and lifecycle expectations for the reusable capability.",
            "Use shared journey, domain, value proposition, and business model canvases to gather technology-agnostic requirements and decide whether the capability should be reusable.",
            "Integration and API work often jumps too quickly to a technical pattern. This station keeps the team focused on the business journey, domain meaning, value, reuse potential, ownership, and viability before selecting APIs, events, files, streams, data products, or direct integration."
          ],
          "outputs": [
            "A technology-agnostic capability opportunity statement",
            "Shared understanding of consumers, producers, domain concepts, and reuse potential",
            "A capability value proposition and business model before architecture selection",
            "design-artifact",
            "documentation",
            "research",
            "roadmap",
            "Documented consumer requirements and onboarding expectations"
          ],
          "recommendedResources": [
            {
              "id": "customerJourneyCanvas",
              "slug": "resources/customer-journey-canvas",
              "title": "Customer Journey Canvas",
              "description": "Map customer, partner, or consumer journeys to identify needs, pain points, gains, inputs, outputs, and experience expectations.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 1,
              "outcomes": [
                "Shared understanding of the customer, partner, or consumer journey",
                "Needs, pain points, gains, inputs, and outputs documented",
                "Journey evidence available for capability, requirements, and architecture decisions"
              ],
              "steps": [
                "Define customer persona",
                "Identify triggers for the journey",
                "Describe the journey's end",
                "Map journey steps with inputs/outputs",
                "Identify customer pains",
                "Summarize customer gains",
                "Define necessary inputs and resulting outputs",
                "Define interactions and processing expectations for each step"
              ],
              "canvasId": "customerJourneyCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "domainCanvas",
              "slug": "resources/domain-canvas",
              "title": "Domain Canvas",
              "description": "A modeling tool to define and communicate the key entities and relationships in your domain, ensuring semantic consistency across capabilities, integrations, APIs, data products, and services.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 152,
              "outcomes": [
                "Shared domain model and terminology",
                "Core entities, relationships, rules, and ownership clarified",
                "Semantic consistency across capabilities, integrations, APIs, data products, and services"
              ],
              "steps": [
                "Define core entities, their attributes, and relationships to create a shared conceptual understanding across capabilities, integrations, APIs, data products, and services."
              ],
              "canvasId": "domainCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capabilityValuePropositionCanvas",
              "slug": "resources/capability-value-proposition-canvas",
              "title": "Capability Value Proposition Canvas",
              "description": "A technology-agnostic canvas for mapping consumer tasks, gains, pains, and candidate reusable capabilities before selecting an implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 2.1,
              "outcomes": [
                "Clear reusable capability value proposition",
                "Consumer tasks, gains, and pains captured without assuming a technology",
                "Candidate reusable capabilities identified for architecture evaluation"
              ],
              "steps": [
                "List the consumer tasks and outcomes the capability should support.",
                "Identify gain-enabling capability features.",
                "Identify pain-relieving capability features.",
                "Group the features into candidate reusable capabilities."
              ],
              "canvasId": "capabilityValuePropositionCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capabilityBusinessModelCanvas",
              "slug": "resources/capability-business-model-canvas",
              "title": "Capability Business Model Canvas",
              "description": "A business model canvas for reusable capabilities, covering value, consumers, ownership, engagement, costs, and benefits without assuming an implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 3.1,
              "outcomes": [
                "Viable reusable capability operating model",
                "Ownership, consumers, channels, partners, and support needs clarified",
                "Costs and benefits visible before architecture commitment"
              ],
              "steps": [
                "Summarize the capability value proposition.",
                "Identify consumer segments and engagement channels.",
                "Define key activities, resources, and partners.",
                "Capture costs and benefits.",
                "Clarify ownership, funding, support, and lifecycle expectations.",
                "Validate the model with consumers, producers, and governance stakeholders."
              ],
              "canvasId": "capabilityBusinessModelCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "consumerExperienceRequirementsCanvas",
              "slug": "resources/consumer-experience-requirements-canvas",
              "title": "Consumer Experience Requirements Canvas",
              "description": "A requirements canvas for consumer experience and non-functional needs that should guide the later architecture and implementation-style decision.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 3.2,
              "outcomes": [
                "Technology-agnostic consumer and service requirements",
                "Experience and non-functional needs captured before design starts",
                "Architecture implications documented for implementation-style selection"
              ],
              "steps": [
                "Capture consumer goals and usage context.",
                "Document availability, timeliness, volume, performance, data quality, and consistency expectations.",
                "Document security, privacy, onboarding, change, observability, support, and recovery expectations.",
                "Summarize what the requirements imply for possible implementation styles."
              ],
              "canvasId": "consumerExperienceRequirementsCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "api-onboarding-best-practices",
              "slug": "resources/api-onboarding-best-practices",
              "title": "API Onboarding Best Practices",
              "description": "Best practices to streamline API consumer onboarding journeys with step-by-step registration, discovery, and first-call guidance.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 121,
              "outcomes": [
                "Shared understanding of the purpose and use of API Onboarding Best Practices",
                "A consistent approach to applying API Onboarding Best Practices",
                "Improved application of the related practices"
              ],
              "steps": [
                "Define the API consumer journey from discovery to troubleshooting, identifying key touchpoints and pain points.",
                "Develop onboarding processes and resources to help API consumers understand how to use APIs effectively.",
                "Document how consumers find and use the API, including onboarding processes and registration."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "interactionCanvas",
              "slug": "resources/interaction-canvas",
              "title": "Interaction Canvas",
              "description": "Define interactions, workflows, inputs, outputs, commands, queries, events, and expected responses to ensure a consistent consumer experience.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 9,
              "outcomes": [
                "Defined interaction model for the selected capability",
                "Inputs, outputs, commands, queries, events, and responses clarified",
                "Validation rules and interaction expectations agreed"
              ],
              "steps": [
                "Map interactions to user, consumer, or system tasks",
                "Define access points, operations, commands, queries, or events for each interaction",
                "Document inputs and outputs for each interaction.",
                "Specify validation rules and constraints",
                "Create interaction models for CRUD, query-driven, command-driven, and event-driven interactions"
              ],
              "canvasId": "interactionCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "contract-first-design",
              "slug": "resources/contract-first-design",
              "title": "Contract First Design",
              "description": "A guideline advocating for API-first approaches using formal contracts (e.g., OpenAPI) to align stakeholders before development.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 146,
              "outcomes": [
                "Shared understanding of the purpose and use of Contract First Design",
                "A consistent approach to applying Contract First Design",
                "Improved application of the related practices"
              ],
              "steps": [
                "Apply contract-first or design-first approaches to ensure API interface contracts are validated before implementation.",
                "Define API interface contracts that outline the expectations, responsibilities, and usage guidelines for each API.",
                "Use standardized formats (e.g., OpenAPI, AsyncAPI) to create machine-readable API interface contracts that are easy to share and validate."
              ],
              "canvasId": null,
              "sourcePath": "src/snippets/api-contract-example.yaml",
              "sourceUrl": null,
              "contentMarkdown": "openapi: 3.0.3\r\ninfo:\r\n  title: Sample Catalog API\r\n  version: 1.0.0\r\n  description: |\r\n    Starter example for a read-only APIOps Cycles API.\r\n    This example keeps the contract audit-friendly and easy to extend.\r\nservers:\r\n  - url: /v1\r\n    description: Versioned API base path\r\ntags:\r\n  - name: catalog\r\n    description: Browse and search catalog items\r\npaths:\r\n  /items:\r\n    get:\r\n      tags: [catalog]\r\n      summary: List catalog items\r\n      description: Returns a paginated list of public catalog items.\r\n      operationId: listItems\r\n      parameters:\r\n        - $ref: \"#/components/parameters/searchTerm\"\r\n        - $ref: \"#/components/parameters/categoryId\"\r\n        - $ref: \"#/components/parameters/page\"\r\n        - $ref: \"#/components/parameters/pageSize\"\r\n      responses:\r\n        \"200\":\r\n          description: Item list\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemListResponse\"\r\n              examples:\r\n                default:\r\n                  value:\r\n                    data:\r\n                      - itemId: item-123\r\n                        slug: blue-widget\r\n                        name: Blue Widget\r\n                        status: published\r\n                    page:\r\n                      number: 1\r\n                      size: 20\r\n                      totalItems: 1\r\n        \"400\":\r\n          $ref: \"#/components/responses/BadRequest\"\r\n        \"429\":\r\n          $ref: \"#/components/responses/TooManyRequests\"\r\n  /items/{itemId}:\r\n    get:\r\n      tags: [catalog]\r\n      summary: Get item by id\r\n      description: Returns a single public catalog item by opaque identifier.\r\n      operationId: getItemById\r\n      parameters:\r\n        - $ref: \"#/components/parameters/itemId\"\r\n      responses:\r\n        \"200\":\r\n          description: Item details\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemDetail\"\r\n        \"400\":\r\n          $ref: \"#/components/responses/BadRequest\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\n  /items/by-slug/{slug}:\r\n    get:\r\n      tags: [catalog]\r\n      summary: Get item by slug\r\n      description: Returns a single item by public slug.\r\n      operationId: getItemBySlug\r\n      parameters:\r\n        - $ref: \"#/components/parameters/slug\"\r\n      responses:\r\n        \"200\":\r\n          description: Item details\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemDetail\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\n  /categories/{categoryId}/items:\r\n    get:\r\n      tags: [catalog]\r\n      summary: List items in category\r\n      description: Returns public items in a category.\r\n      operationId: listItemsByCategory\r\n      parameters:\r\n        - $ref: \"#/components/parameters/categoryId\"\r\n      responses:\r\n        \"200\":\r\n          description: Category item list\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemListResponse\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\ncomponents:\r\n  parameters:\r\n    itemId:\r\n      name: itemId\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9][a-z0-9-]{1,63}$\"\r\n      example: item-123\r\n    slug:\r\n      name: slug\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9]+(?:-[a-z0-9]+)*$\"\r\n      example: blue-widget\r\n    categoryId:\r\n      name: categoryId\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9][a-z0-9-]{1,63}$\"\r\n      example: home-goods\r\n    searchTerm:\r\n      name: searchTerm\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: string\r\n        minLength: 1\r\n      example: widget\r\n    page:\r\n      name: page\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: integer\r\n        minimum: 1\r\n        default: 1\r\n    pageSize:\r\n      name: pageSize\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: integer\r\n        minimum: 1\r\n        maximum: 100\r\n        default: 20\r\n  responses:\r\n    BadRequest:\r\n      description: Validation failed\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n          examples:\r\n            default:\r\n              value:\r\n                code: BAD_REQUEST\r\n                message: Invalid request\r\n    NotFound:\r\n      description: Resource not found\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n    TooManyRequests:\r\n      description: Rate limit exceeded\r\n      headers:\r\n        Retry-After:\r\n          schema:\r\n            type: integer\r\n          description: Seconds until the next allowed request.\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n  schemas:\r\n    ItemListResponse:\r\n      type: object\r\n      required: [data, page]\r\n      properties:\r\n        data:\r\n          type: array\r\n          items:\r\n            $ref: \"#/components/schemas/ItemSummary\"\r\n        page:\r\n          $ref: \"#/components/schemas/Page\"\r\n    ItemSummary:\r\n      type: object\r\n      required: [itemId, slug, name, status]\r\n      properties:\r\n        itemId:\r\n          type: string\r\n        slug:\r\n          type: string\r\n        name:\r\n          type: string\r\n        status:\r\n          type: string\r\n          enum: [published, hidden]\r\n    ItemDetail:\r\n      allOf:\r\n        - $ref: \"#/components/schemas/ItemSummary\"\r\n        - type: object\r\n          properties:\r\n            description:\r\n              type: string\r\n            categories:\r\n              type: array\r\n              items:\r\n                type: string\r\n            variants:\r\n              type: array\r\n              items:\r\n                $ref: \"#/components/schemas/Variant\"\r\n    Variant:\r\n      type: object\r\n      required: [variantId, sku, price, inventory]\r\n      properties:\r\n        variantId:\r\n          type: string\r\n        sku:\r\n          type: string\r\n        price:\r\n          $ref: \"#/components/schemas/Price\"\r\n        inventory:\r\n          $ref: \"#/components/schemas/Inventory\"\r\n    Price:\r\n      type: object\r\n      required: [amount, currency]\r\n      properties:\r\n        amount:\r\n          type: number\r\n          format: decimal\r\n        currency:\r\n          type: string\r\n          example: EUR\r\n    Inventory:\r\n      type: object\r\n      required: [available]\r\n      properties:\r\n        available:\r\n          type: integer\r\n          minimum: 0\r\n        reserved:\r\n          type: integer\r\n          minimum: 0\r\n        source:\r\n          type: string\r\n    Page:\r\n      type: object\r\n      required: [number, size, totalItems]\r\n      properties:\r\n        number:\r\n          type: integer\r\n        size:\r\n          type: integer\r\n        totalItems:\r\n          type: integer\r\n    ErrorResponse:\r\n      type: object\r\n      required: [code, message]\r\n      properties:\r\n        code:\r\n          type: string\r\n        message:\r\n          type: string\r\n",
              "draft": true
            },
            {
              "id": "businessImpactCanvas",
              "slug": "resources/business-impact-canvas",
              "title": "Business Impact Canvas",
              "description": "Identify business, availability, security, data, compliance, and operational risks that should shape architecture and platform decisions.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 4,
              "outcomes": [
                "Documented business and operational impact assessment",
                "Prioritized risks and mitigation actions",
                "Evidence for architecture and platform decisions"
              ],
              "steps": [
                "Availability Risks: Identify risks and impacts.",
                "Ways to Mitigate Availability Risks: Define mitigation measures.",
                "Security Risks: Document security-related risks.",
                "Ways to Mitigate Security Risks: Propose strategies to mitigate security risks.",
                "Data Risks: Identify risks to data accuracy or availability.",
                "Ways to Mitigate Data Risks: Plan strategies to address data risks."
              ],
              "canvasId": "businessImpactCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "locationsCanvas",
              "slug": "resources/location-canvas",
              "title": "Location Canvas",
              "description": "Map consumer, producer, system, data, network, regulatory, and trust-boundary locations to ensure compliance and performance across regions.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 6,
              "outcomes": [
                "Documented location, residency, network, and regulatory requirements",
                "Regional performance and accessibility constraints identified",
                "Data residency, trust boundaries, and applicable regulations clarified"
              ],
              "steps": [
                "Map locations of producers, source systems, platforms, and consumers.",
                "Document where consumers are located.",
                "Identify applicable regulations.",
                "Document where data must reside.",
                "Ensure the capability is accessible in all intended network regions.",
                "Validate network performance across regions."
              ],
              "canvasId": "locationsCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            }
          ],
          "promptIds": [
            "domain-specialist:facilitate-station",
            "domain-specialist:use-resources",
            "domain-specialist:next-actions"
          ]
        },
        {
          "id": "integration-architect",
          "stakeholderId": "integration-architect",
          "title": "Integration Architect",
          "summary": "Designs integration approaches and implementation styles that connect the capability or API with other systems.",
          "stakeholder": {
            "id": "integration-architect",
            "sourceKey": "integration-architect",
            "sourceStakeholderId": "integration-architect",
            "title": "Integration Architect",
            "description": "Designs integration approaches and implementation styles that connect the capability or API with other systems.",
            "involvement": ""
          },
          "cycles": [
            {
              "id": "capability-productization-cycle",
              "title": "Capability Productization Cycle",
              "description": "A cycle for turning business capabilities into reusable digital capabilities before selecting the implementation style."
            },
            {
              "id": "integration-productization-cycle",
              "title": "Integration Productization Cycle",
              "description": "A cycle for productizing reusable integration capabilities before selecting the implementation style."
            },
            {
              "id": "automation-cycle",
              "title": "Automation Cycle",
              "description": "A cycle for identifying, designing, delivering, enabling, and improving automation opportunities."
            }
          ],
          "stations": [
            {
              "id": "api-platform-architecture",
              "title": "Architecture & Platform Decisions",
              "description": "Use requirements and constraints to decide the right architecture pattern and enabling platform capabilities."
            },
            {
              "id": "api-design",
              "title": "Solution & Interface Design",
              "description": "Design the interface contract and interaction model after the architecture choice is justified."
            },
            {
              "id": "api-product-strategy",
              "title": "Strategy",
              "description": "Frame the business need as a reusable capability before choosing the implementation style."
            },
            {
              "id": "api-consumer-experience",
              "title": "Consumer Requirements & Onboarding",
              "description": "Capture consumer onboarding, standards, non-functional requirements, service expectations, constraints, security needs, allowed protocols, data freshness, SLAs, observability, recovery, adoption requirements, and producer responsibilities."
            },
            {
              "id": "api-delivery",
              "title": "Delivery & Operations",
              "description": "Deliver the selected implementation style with appropriate engineering, testing, security, automation, and operational practices."
            },
            {
              "id": "api-audit",
              "title": "Quality & Readiness Assurance",
              "description": "Audit the capability interface contract, controls, support model, observability, documentation, and lifecycle readiness before release."
            },
            {
              "id": "api-publishing",
              "title": "Publishing & Enablement",
              "description": "Publish reusable capability information so consumers can discover, request, onboard, use, and get support."
            },
            {
              "id": "monitoring-and-improving",
              "title": "Monitoring & Improvement",
              "description": "Monitor usage, reliability, data quality, consumer outcomes, operational cost, and reuse opportunities after release."
            }
          ],
          "canvases": [
            {
              "id": "businessImpactCanvas",
              "title": "Business Impact Canvas"
            },
            {
              "id": "locationsCanvas",
              "title": "Locations Canvas"
            },
            {
              "id": "capacityCanvas",
              "title": "Capacity Canvas"
            },
            {
              "id": "domainCanvas",
              "title": "Domain Canvas"
            },
            {
              "id": "interactionCanvas",
              "title": "Interaction Canvas"
            },
            {
              "id": "customerJourneyCanvas",
              "title": "Customer Journey Canvas"
            },
            {
              "id": "capabilityValuePropositionCanvas",
              "title": "Capability Value Proposition Canvas"
            },
            {
              "id": "capabilityBusinessModelCanvas",
              "title": "Capability Business Model Canvas"
            },
            {
              "id": "consumerExperienceRequirementsCanvas",
              "title": "Consumer Experience Requirements Canvas"
            },
            {
              "id": "restCanvas",
              "title": "REST Canvas"
            },
            {
              "id": "eventCanvas",
              "title": "Event Canvas"
            },
            {
              "id": "graphqlCanvas",
              "title": "GraphQL Canvas"
            }
          ],
          "decisions": [
            "Use the Business Impact Canvas to identify availability, security, and data risks that influence architecture options.",
            "Use the Locations Canvas to capture geopolitical, regulatory, network, residency, and trust-boundary constraints.",
            "Use the Capacity Canvas to capture current and future volumes, peaks, latency, caching, rate limiting, and scaling expectations.",
            "Use metrics and analytics guidance to define how the chosen capability will be monitored and improved.",
            "Compare viable architecture styles against the gathered requirements and document the selected pattern and rationale.",
            "Architecture choices should follow from evidence about business impact, locations, trust boundaries, capacity, latency, data ownership, consistency, operability, security, privacy, governance, and cost."
          ],
          "outputs": [
            "A justified architecture choice",
            "Documented risks, locations, capacity, security, privacy, and operability constraints",
            "Clear rationale for API, event, file, stream, data product, direct integration, or hybrid implementation style",
            "architecture-decision",
            "documentation",
            "platform-config",
            "metrics",
            "A validated interface contract for the selected implementation style"
          ],
          "recommendedResources": [
            {
              "id": "businessImpactCanvas",
              "slug": "resources/business-impact-canvas",
              "title": "Business Impact Canvas",
              "description": "Identify business, availability, security, data, compliance, and operational risks that should shape architecture and platform decisions.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 4,
              "outcomes": [
                "Documented business and operational impact assessment",
                "Prioritized risks and mitigation actions",
                "Evidence for architecture and platform decisions"
              ],
              "steps": [
                "Availability Risks: Identify risks and impacts.",
                "Ways to Mitigate Availability Risks: Define mitigation measures.",
                "Security Risks: Document security-related risks.",
                "Ways to Mitigate Security Risks: Propose strategies to mitigate security risks.",
                "Data Risks: Identify risks to data accuracy or availability.",
                "Ways to Mitigate Data Risks: Plan strategies to address data risks."
              ],
              "canvasId": "businessImpactCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "locationsCanvas",
              "slug": "resources/location-canvas",
              "title": "Location Canvas",
              "description": "Map consumer, producer, system, data, network, regulatory, and trust-boundary locations to ensure compliance and performance across regions.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 6,
              "outcomes": [
                "Documented location, residency, network, and regulatory requirements",
                "Regional performance and accessibility constraints identified",
                "Data residency, trust boundaries, and applicable regulations clarified"
              ],
              "steps": [
                "Map locations of producers, source systems, platforms, and consumers.",
                "Document where consumers are located.",
                "Identify applicable regulations.",
                "Document where data must reside.",
                "Ensure the capability is accessible in all intended network regions.",
                "Validate network performance across regions."
              ],
              "canvasId": "locationsCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capacityCanvas",
              "slug": "resources/capacity-canvas",
              "title": "Capacity Canvas",
              "description": "Plan capacity for current and future demand, including volumes, peaks, latency, availability, scaling, caching, and rate limits for the selected capability and implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 7,
              "outcomes": [
                "Capacity requirements aligned with expected business demand",
                "Peak-load, availability, and growth assumptions documented",
                "Scaling, caching, and rate-limiting decisions defined"
              ],
              "steps": [
                "Document current business volumes",
                "Forecast future consumption trends",
                "Plan for peak load and availability requirements",
                "Define caching and rate-limiting strategies",
                "Propose scaling strategies"
              ],
              "canvasId": "capacityCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "domainCanvas",
              "slug": "resources/domain-canvas",
              "title": "Domain Canvas",
              "description": "A modeling tool to define and communicate the key entities and relationships in your domain, ensuring semantic consistency across capabilities, integrations, APIs, data products, and services.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 152,
              "outcomes": [
                "Shared domain model and terminology",
                "Core entities, relationships, rules, and ownership clarified",
                "Semantic consistency across capabilities, integrations, APIs, data products, and services"
              ],
              "steps": [
                "Define core entities, their attributes, and relationships to create a shared conceptual understanding across capabilities, integrations, APIs, data products, and services."
              ],
              "canvasId": "domainCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "interactionCanvas",
              "slug": "resources/interaction-canvas",
              "title": "Interaction Canvas",
              "description": "Define interactions, workflows, inputs, outputs, commands, queries, events, and expected responses to ensure a consistent consumer experience.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 9,
              "outcomes": [
                "Defined interaction model for the selected capability",
                "Inputs, outputs, commands, queries, events, and responses clarified",
                "Validation rules and interaction expectations agreed"
              ],
              "steps": [
                "Map interactions to user, consumer, or system tasks",
                "Define access points, operations, commands, queries, or events for each interaction",
                "Document inputs and outputs for each interaction.",
                "Specify validation rules and constraints",
                "Create interaction models for CRUD, query-driven, command-driven, and event-driven interactions"
              ],
              "canvasId": "interactionCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "contract-first-design",
              "slug": "resources/contract-first-design",
              "title": "Contract First Design",
              "description": "A guideline advocating for API-first approaches using formal contracts (e.g., OpenAPI) to align stakeholders before development.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 146,
              "outcomes": [
                "Shared understanding of the purpose and use of Contract First Design",
                "A consistent approach to applying Contract First Design",
                "Improved application of the related practices"
              ],
              "steps": [
                "Apply contract-first or design-first approaches to ensure API interface contracts are validated before implementation.",
                "Define API interface contracts that outline the expectations, responsibilities, and usage guidelines for each API.",
                "Use standardized formats (e.g., OpenAPI, AsyncAPI) to create machine-readable API interface contracts that are easy to share and validate."
              ],
              "canvasId": null,
              "sourcePath": "src/snippets/api-contract-example.yaml",
              "sourceUrl": null,
              "contentMarkdown": "openapi: 3.0.3\r\ninfo:\r\n  title: Sample Catalog API\r\n  version: 1.0.0\r\n  description: |\r\n    Starter example for a read-only APIOps Cycles API.\r\n    This example keeps the contract audit-friendly and easy to extend.\r\nservers:\r\n  - url: /v1\r\n    description: Versioned API base path\r\ntags:\r\n  - name: catalog\r\n    description: Browse and search catalog items\r\npaths:\r\n  /items:\r\n    get:\r\n      tags: [catalog]\r\n      summary: List catalog items\r\n      description: Returns a paginated list of public catalog items.\r\n      operationId: listItems\r\n      parameters:\r\n        - $ref: \"#/components/parameters/searchTerm\"\r\n        - $ref: \"#/components/parameters/categoryId\"\r\n        - $ref: \"#/components/parameters/page\"\r\n        - $ref: \"#/components/parameters/pageSize\"\r\n      responses:\r\n        \"200\":\r\n          description: Item list\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemListResponse\"\r\n              examples:\r\n                default:\r\n                  value:\r\n                    data:\r\n                      - itemId: item-123\r\n                        slug: blue-widget\r\n                        name: Blue Widget\r\n                        status: published\r\n                    page:\r\n                      number: 1\r\n                      size: 20\r\n                      totalItems: 1\r\n        \"400\":\r\n          $ref: \"#/components/responses/BadRequest\"\r\n        \"429\":\r\n          $ref: \"#/components/responses/TooManyRequests\"\r\n  /items/{itemId}:\r\n    get:\r\n      tags: [catalog]\r\n      summary: Get item by id\r\n      description: Returns a single public catalog item by opaque identifier.\r\n      operationId: getItemById\r\n      parameters:\r\n        - $ref: \"#/components/parameters/itemId\"\r\n      responses:\r\n        \"200\":\r\n          description: Item details\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemDetail\"\r\n        \"400\":\r\n          $ref: \"#/components/responses/BadRequest\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\n  /items/by-slug/{slug}:\r\n    get:\r\n      tags: [catalog]\r\n      summary: Get item by slug\r\n      description: Returns a single item by public slug.\r\n      operationId: getItemBySlug\r\n      parameters:\r\n        - $ref: \"#/components/parameters/slug\"\r\n      responses:\r\n        \"200\":\r\n          description: Item details\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemDetail\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\n  /categories/{categoryId}/items:\r\n    get:\r\n      tags: [catalog]\r\n      summary: List items in category\r\n      description: Returns public items in a category.\r\n      operationId: listItemsByCategory\r\n      parameters:\r\n        - $ref: \"#/components/parameters/categoryId\"\r\n      responses:\r\n        \"200\":\r\n          description: Category item list\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemListResponse\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\ncomponents:\r\n  parameters:\r\n    itemId:\r\n      name: itemId\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9][a-z0-9-]{1,63}$\"\r\n      example: item-123\r\n    slug:\r\n      name: slug\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9]+(?:-[a-z0-9]+)*$\"\r\n      example: blue-widget\r\n    categoryId:\r\n      name: categoryId\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9][a-z0-9-]{1,63}$\"\r\n      example: home-goods\r\n    searchTerm:\r\n      name: searchTerm\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: string\r\n        minLength: 1\r\n      example: widget\r\n    page:\r\n      name: page\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: integer\r\n        minimum: 1\r\n        default: 1\r\n    pageSize:\r\n      name: pageSize\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: integer\r\n        minimum: 1\r\n        maximum: 100\r\n        default: 20\r\n  responses:\r\n    BadRequest:\r\n      description: Validation failed\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n          examples:\r\n            default:\r\n              value:\r\n                code: BAD_REQUEST\r\n                message: Invalid request\r\n    NotFound:\r\n      description: Resource not found\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n    TooManyRequests:\r\n      description: Rate limit exceeded\r\n      headers:\r\n        Retry-After:\r\n          schema:\r\n            type: integer\r\n          description: Seconds until the next allowed request.\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n  schemas:\r\n    ItemListResponse:\r\n      type: object\r\n      required: [data, page]\r\n      properties:\r\n        data:\r\n          type: array\r\n          items:\r\n            $ref: \"#/components/schemas/ItemSummary\"\r\n        page:\r\n          $ref: \"#/components/schemas/Page\"\r\n    ItemSummary:\r\n      type: object\r\n      required: [itemId, slug, name, status]\r\n      properties:\r\n        itemId:\r\n          type: string\r\n        slug:\r\n          type: string\r\n        name:\r\n          type: string\r\n        status:\r\n          type: string\r\n          enum: [published, hidden]\r\n    ItemDetail:\r\n      allOf:\r\n        - $ref: \"#/components/schemas/ItemSummary\"\r\n        - type: object\r\n          properties:\r\n            description:\r\n              type: string\r\n            categories:\r\n              type: array\r\n              items:\r\n                type: string\r\n            variants:\r\n              type: array\r\n              items:\r\n                $ref: \"#/components/schemas/Variant\"\r\n    Variant:\r\n      type: object\r\n      required: [variantId, sku, price, inventory]\r\n      properties:\r\n        variantId:\r\n          type: string\r\n        sku:\r\n          type: string\r\n        price:\r\n          $ref: \"#/components/schemas/Price\"\r\n        inventory:\r\n          $ref: \"#/components/schemas/Inventory\"\r\n    Price:\r\n      type: object\r\n      required: [amount, currency]\r\n      properties:\r\n        amount:\r\n          type: number\r\n          format: decimal\r\n        currency:\r\n          type: string\r\n          example: EUR\r\n    Inventory:\r\n      type: object\r\n      required: [available]\r\n      properties:\r\n        available:\r\n          type: integer\r\n          minimum: 0\r\n        reserved:\r\n          type: integer\r\n          minimum: 0\r\n        source:\r\n          type: string\r\n    Page:\r\n      type: object\r\n      required: [number, size, totalItems]\r\n      properties:\r\n        number:\r\n          type: integer\r\n        size:\r\n          type: integer\r\n        totalItems:\r\n          type: integer\r\n    ErrorResponse:\r\n      type: object\r\n      required: [code, message]\r\n      properties:\r\n        code:\r\n          type: string\r\n        message:\r\n          type: string\r\n",
              "draft": true
            },
            {
              "id": "customerJourneyCanvas",
              "slug": "resources/customer-journey-canvas",
              "title": "Customer Journey Canvas",
              "description": "Map customer, partner, or consumer journeys to identify needs, pain points, gains, inputs, outputs, and experience expectations.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 1,
              "outcomes": [
                "Shared understanding of the customer, partner, or consumer journey",
                "Needs, pain points, gains, inputs, and outputs documented",
                "Journey evidence available for capability, requirements, and architecture decisions"
              ],
              "steps": [
                "Define customer persona",
                "Identify triggers for the journey",
                "Describe the journey's end",
                "Map journey steps with inputs/outputs",
                "Identify customer pains",
                "Summarize customer gains",
                "Define necessary inputs and resulting outputs",
                "Define interactions and processing expectations for each step"
              ],
              "canvasId": "customerJourneyCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capabilityValuePropositionCanvas",
              "slug": "resources/capability-value-proposition-canvas",
              "title": "Capability Value Proposition Canvas",
              "description": "A technology-agnostic canvas for mapping consumer tasks, gains, pains, and candidate reusable capabilities before selecting an implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 2.1,
              "outcomes": [
                "Clear reusable capability value proposition",
                "Consumer tasks, gains, and pains captured without assuming a technology",
                "Candidate reusable capabilities identified for architecture evaluation"
              ],
              "steps": [
                "List the consumer tasks and outcomes the capability should support.",
                "Identify gain-enabling capability features.",
                "Identify pain-relieving capability features.",
                "Group the features into candidate reusable capabilities."
              ],
              "canvasId": "capabilityValuePropositionCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capabilityBusinessModelCanvas",
              "slug": "resources/capability-business-model-canvas",
              "title": "Capability Business Model Canvas",
              "description": "A business model canvas for reusable capabilities, covering value, consumers, ownership, engagement, costs, and benefits without assuming an implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 3.1,
              "outcomes": [
                "Viable reusable capability operating model",
                "Ownership, consumers, channels, partners, and support needs clarified",
                "Costs and benefits visible before architecture commitment"
              ],
              "steps": [
                "Summarize the capability value proposition.",
                "Identify consumer segments and engagement channels.",
                "Define key activities, resources, and partners.",
                "Capture costs and benefits.",
                "Clarify ownership, funding, support, and lifecycle expectations.",
                "Validate the model with consumers, producers, and governance stakeholders."
              ],
              "canvasId": "capabilityBusinessModelCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "consumerExperienceRequirementsCanvas",
              "slug": "resources/consumer-experience-requirements-canvas",
              "title": "Consumer Experience Requirements Canvas",
              "description": "A requirements canvas for consumer experience and non-functional needs that should guide the later architecture and implementation-style decision.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 3.2,
              "outcomes": [
                "Technology-agnostic consumer and service requirements",
                "Experience and non-functional needs captured before design starts",
                "Architecture implications documented for implementation-style selection"
              ],
              "steps": [
                "Capture consumer goals and usage context.",
                "Document availability, timeliness, volume, performance, data quality, and consistency expectations.",
                "Document security, privacy, onboarding, change, observability, support, and recovery expectations.",
                "Summarize what the requirements imply for possible implementation styles."
              ],
              "canvasId": "consumerExperienceRequirementsCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            }
          ],
          "promptIds": [
            "integration-architect:facilitate-station",
            "integration-architect:use-resources",
            "integration-architect:next-actions"
          ]
        },
        {
          "id": "partner-specialist",
          "stakeholderId": "partner-specialist",
          "title": "Partner or Vendor Manager",
          "summary": "Coordinates external partner, supplier, or vendor relationships that influence capability or API strategy and delivery.",
          "stakeholder": {
            "id": "partner-specialist",
            "sourceKey": "partner-specialist",
            "sourceStakeholderId": "partner-specialist",
            "title": "Partner or Vendor Manager",
            "description": "Coordinates external partner, supplier, or vendor relationships that influence capability or API strategy and delivery.",
            "involvement": ""
          },
          "cycles": [
            {
              "id": "capability-productization-cycle",
              "title": "Capability Productization Cycle",
              "description": "A cycle for turning business capabilities into reusable digital capabilities before selecting the implementation style."
            },
            {
              "id": "integration-productization-cycle",
              "title": "Integration Productization Cycle",
              "description": "A cycle for productizing reusable integration capabilities before selecting the implementation style."
            }
          ],
          "stations": [
            {
              "id": "api-publishing",
              "title": "Publishing & Enablement",
              "description": "Publish reusable capability information so consumers can discover, request, onboard, use, and get support."
            },
            {
              "id": "api-product-strategy",
              "title": "Strategy",
              "description": "Frame the business need as a reusable capability before choosing the implementation style."
            },
            {
              "id": "api-consumer-experience",
              "title": "Consumer Requirements & Onboarding",
              "description": "Capture consumer onboarding, standards, non-functional requirements, service expectations, constraints, security needs, allowed protocols, data freshness, SLAs, observability, recovery, adoption requirements, and producer responsibilities."
            },
            {
              "id": "api-delivery",
              "title": "Delivery & Operations",
              "description": "Deliver the selected implementation style with appropriate engineering, testing, security, automation, and operational practices."
            }
          ],
          "canvases": [
            {
              "id": "customerJourneyCanvas",
              "title": "Customer Journey Canvas"
            },
            {
              "id": "domainCanvas",
              "title": "Domain Canvas"
            },
            {
              "id": "capabilityValuePropositionCanvas",
              "title": "Capability Value Proposition Canvas"
            },
            {
              "id": "capabilityBusinessModelCanvas",
              "title": "Capability Business Model Canvas"
            },
            {
              "id": "consumerExperienceRequirementsCanvas",
              "title": "Consumer Experience Requirements Canvas"
            }
          ],
          "decisions": [
            "Publish capability information to the appropriate catalogs, portals, gateways, or environments to support reuse by multiple consumers.",
            "Document how consumers find and use the capability, including onboarding processes and registration.",
            "Ensure security models, access configuration, and legal terms are clear and accessible to consumers.",
            "Publish ownership, documentation, onboarding, support contacts, service expectations, lifecycle status, and access request paths.",
            "Reusable capabilities only create value when consumers can find them, understand their interface contract and service expectations, request access, and know who owns support and lifecycle decisions.",
            "Map the customer or partner journey that creates the capability need and reveals tasks, pains, gains, inputs, outputs, and decision points."
          ],
          "outputs": [
            "A discoverable reusable capability",
            "Clear onboarding, access, support, and service expectations",
            "Lifecycle and ownership information available to consumers and governance teams",
            "Consumers enabled to use and reuse the capability",
            "gateway-config",
            "developer-portal",
            "documentation",
            "release-record"
          ],
          "recommendedResources": [
            {
              "id": "api-onboarding-best-practices",
              "slug": "resources/api-onboarding-best-practices",
              "title": "API Onboarding Best Practices",
              "description": "Best practices to streamline API consumer onboarding journeys with step-by-step registration, discovery, and first-call guidance.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 121,
              "outcomes": [
                "Shared understanding of the purpose and use of API Onboarding Best Practices",
                "A consistent approach to applying API Onboarding Best Practices",
                "Improved application of the related practices"
              ],
              "steps": [
                "Define the API consumer journey from discovery to troubleshooting, identifying key touchpoints and pain points.",
                "Develop onboarding processes and resources to help API consumers understand how to use APIs effectively.",
                "Document how consumers find and use the API, including onboarding processes and registration."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "service-agreement-template",
              "slug": "resources/service-agreement-template",
              "title": "Service Agreement Template",
              "description": "A customizable agreement format that defines expectations, SLAs, responsibilities, and access terms for API consumption.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 172,
              "outcomes": [
                "Shared understanding of the purpose and use of Service Agreement Template",
                "A consistent approach to applying Service Agreement Template",
                "Improved application of the related practices"
              ],
              "steps": [
                "Define service agreements that outline the expectations, service levels, and responsibilities for each API.",
                "Use standardized formats to create machine-readable service agreements that are easy to share and validate.",
                "Ensure service agreements are reviewed and approved by stakeholders to ensure alignment and clarity."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "customerJourneyCanvas",
              "slug": "resources/customer-journey-canvas",
              "title": "Customer Journey Canvas",
              "description": "Map customer, partner, or consumer journeys to identify needs, pain points, gains, inputs, outputs, and experience expectations.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 1,
              "outcomes": [
                "Shared understanding of the customer, partner, or consumer journey",
                "Needs, pain points, gains, inputs, and outputs documented",
                "Journey evidence available for capability, requirements, and architecture decisions"
              ],
              "steps": [
                "Define customer persona",
                "Identify triggers for the journey",
                "Describe the journey's end",
                "Map journey steps with inputs/outputs",
                "Identify customer pains",
                "Summarize customer gains",
                "Define necessary inputs and resulting outputs",
                "Define interactions and processing expectations for each step"
              ],
              "canvasId": "customerJourneyCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "domainCanvas",
              "slug": "resources/domain-canvas",
              "title": "Domain Canvas",
              "description": "A modeling tool to define and communicate the key entities and relationships in your domain, ensuring semantic consistency across capabilities, integrations, APIs, data products, and services.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 152,
              "outcomes": [
                "Shared domain model and terminology",
                "Core entities, relationships, rules, and ownership clarified",
                "Semantic consistency across capabilities, integrations, APIs, data products, and services"
              ],
              "steps": [
                "Define core entities, their attributes, and relationships to create a shared conceptual understanding across capabilities, integrations, APIs, data products, and services."
              ],
              "canvasId": "domainCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capabilityValuePropositionCanvas",
              "slug": "resources/capability-value-proposition-canvas",
              "title": "Capability Value Proposition Canvas",
              "description": "A technology-agnostic canvas for mapping consumer tasks, gains, pains, and candidate reusable capabilities before selecting an implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 2.1,
              "outcomes": [
                "Clear reusable capability value proposition",
                "Consumer tasks, gains, and pains captured without assuming a technology",
                "Candidate reusable capabilities identified for architecture evaluation"
              ],
              "steps": [
                "List the consumer tasks and outcomes the capability should support.",
                "Identify gain-enabling capability features.",
                "Identify pain-relieving capability features.",
                "Group the features into candidate reusable capabilities."
              ],
              "canvasId": "capabilityValuePropositionCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capabilityBusinessModelCanvas",
              "slug": "resources/capability-business-model-canvas",
              "title": "Capability Business Model Canvas",
              "description": "A business model canvas for reusable capabilities, covering value, consumers, ownership, engagement, costs, and benefits without assuming an implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 3.1,
              "outcomes": [
                "Viable reusable capability operating model",
                "Ownership, consumers, channels, partners, and support needs clarified",
                "Costs and benefits visible before architecture commitment"
              ],
              "steps": [
                "Summarize the capability value proposition.",
                "Identify consumer segments and engagement channels.",
                "Define key activities, resources, and partners.",
                "Capture costs and benefits.",
                "Clarify ownership, funding, support, and lifecycle expectations.",
                "Validate the model with consumers, producers, and governance stakeholders."
              ],
              "canvasId": "capabilityBusinessModelCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "consumerExperienceRequirementsCanvas",
              "slug": "resources/consumer-experience-requirements-canvas",
              "title": "Consumer Experience Requirements Canvas",
              "description": "A requirements canvas for consumer experience and non-functional needs that should guide the later architecture and implementation-style decision.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 3.2,
              "outcomes": [
                "Technology-agnostic consumer and service requirements",
                "Experience and non-functional needs captured before design starts",
                "Architecture implications documented for implementation-style selection"
              ],
              "steps": [
                "Capture consumer goals and usage context.",
                "Document availability, timeliness, volume, performance, data quality, and consistency expectations.",
                "Document security, privacy, onboarding, change, observability, support, and recovery expectations.",
                "Summarize what the requirements imply for possible implementation styles."
              ],
              "canvasId": "consumerExperienceRequirementsCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "api-development-best-practices",
              "slug": "resources/api-development-best-practices",
              "title": "API Development Best Practices",
              "description": "Implementation guidance for turning a validated API interface contract into a consistent, maintainable API codebase using standard libraries, reusable patterns, and aligned development workflows.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 112,
              "outcomes": [
                "Shared understanding of the purpose and use of API Development Best Practices",
                "A consistent approach to applying API Development Best Practices",
                "Improved application of the related practices"
              ],
              "steps": [
                "Apply these practices to the validated API interface contract and implementation plan before coding begins.",
                "Use established frameworks, libraries, and coding standards to implement the contract consistently and maintainably."
              ],
              "canvasId": null,
              "sourcePath": "src/snippets/api-design-principles-guidance.md",
              "sourceUrl": null,
              "contentMarkdown": "## How to start the API Delivery work based on the previous phases (\"stations\")\r\n\r\nUse this guidance at the start of `API Delivery` after the API contract (e.g. OpenAPI) and the key outputs from earlier stations have been reviewed and accepted.\r\n\r\nThe goal is not to invent implementation in isolation. The goal is to turn the agreed outputs from earlier stations into concrete code structure, validation rules, runtime behavior, and API product delivery decisions.\r\n\r\n---\r\n\r\n### 1. Start From The Validated Contract\r\n\r\n- Treat the validated API contract as the main reference point for implementation decisions.\r\n- Keep the contract and implementation aligned throughout the API product delivery.\r\n- Use the contract to drive request validation, response mapping, documentation, and tests.\r\n\r\n---\r\n\r\n### 2. Use Domain Outputs To Preserve Business Meaning\r\n\r\n- Use the `Domain Canvas` outputs to guide naming, how the implementation is split into clear business responsibilities, and how different backend systems are connected without exposing their differences.\r\n- Preserve the validated meanings of entities, attributes, statuses, and source-of-truth rules.\r\n- Avoid leaking backend-specific models or inconsistencies into the public API.\r\n\r\n---\r\n\r\n### 3. Use Journey Outputs To Preserve Critical Flows\r\n\r\n- Use the `Customer Journey Canvas` outputs to identify which user flows are most important to support first.\r\n- Use the `API Consumer Experience` outputs to keep the API understandable, predictable, and easy to integrate.\r\n- Let the agreed journey priorities decide which implementation paths need the highest reliability, lowest latency, clearest errors, and strongest operational focus.\r\n\r\n---\r\n\r\n### 4. Use Value Proposition Outputs To Preserve Consumer Value\r\n\r\n- Use the `API Value Proposition Canvas` outputs to keep the implementation focused on the agreed pains, gains, and API features.\r\n- Preserve the field meanings, behavior, and promises that made the API valuable in the earlier stations.\r\n- Ensure error handling, freshness, and naming support both the intended developer experience and the business use case.\r\n\r\n---\r\n\r\n### 5. Use Architecture Outputs To Shape Runtime Decisions\r\n\r\n- Use the `Business Impact Canvas` outputs to guide resilience, timeout, fallback, and degradation decisions.\r\n- Use the `Locations Canvas` outputs to guide network boundaries, trust boundaries, access paths, and deployment constraints.\r\n- Use the `Capacity Canvas` outputs to guide rate limits, caching, scaling, and peak-load behavior.\r\n- Use the `API Metrics And Analytics` guidance to decide what must be observed from the first implementation onward.\r\n\r\n---\r\n\r\n### 6. Use Interaction And Protocol Design Outputs To Shape Code Structure\r\n\r\n- Use the `Interaction Canvas` outputs to avoid implementing unsupported interaction styles too early.\r\n- Use the `REST`, `Event`, or `GraphQL` design outputs to shape protocol-specific request, response, and validation behavior.\r\n- Reflect the selected interaction style clearly in code structure, responsibilities, and testing strategy.\r\n\r\n---\r\n\r\n### 7. Use Audit Outputs To Improve Delivery Before Coding Goes Too Far\r\n\r\n- Use the audit findings to remove ambiguity before implementation spreads across the codebase.\r\n- Fix unclear request rules, missing validation, weak error contracts, and operational gaps early.\r\n- Treat audit as a design-improvement loop before production, not only as a final decision gate.\r\n\r\n---\r\n\r\n### 8. Apply The Guidance, Then Summarize\r\n\r\n- Apply this guidance to the current API and implementation plan.\r\n- Summarize the implications for code structure, request validation, source integration, security, monitoring and alerts, and testing.\r\n- Do not create a separate delivery artifact unless the team or user specifically needs one.\r\n",
              "draft": true
            },
            {
              "id": "api-testing-best-practices",
              "slug": "resources/api-testing-best-practices",
              "title": "API Testing Best Practices",
              "description": "Guidelines for implementing automated functional, performance, and security testing throughout the API lifecycle.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 133,
              "outcomes": [
                "Shared understanding of the purpose and use of API Testing Best Practices",
                "A consistent approach to applying API Testing Best Practices",
                "Improved application of the related practices"
              ],
              "steps": [
                "Test APIs for functionality, security, and performance using automated testing tools.",
                "Integrate functional and non-functional testing into the CI/CD pipeline to ensure APIs meet quality standards.",
                "Use automated testing tools to validate API functionality, security, and performance."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "apiops-CI-CD-for-apis",
              "slug": "resources/apiops-CI-CD-for-apis",
              "title": "APIOps CI/CD For APIs",
              "description": "Deployment guidance that integrates API lifecycle tasks—design, testing, governance—into continuous integration and delivery pipelines.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 140,
              "outcomes": [
                "Shared understanding of the purpose and use of APIOps CI/CD For APIs",
                "A consistent approach to applying APIOps CI/CD For APIs",
                "Improved application of the related practices"
              ],
              "steps": [
                "Use CI/CD pipelines to automate build, test, and deployment processes, ensuring consistent quality and traceability.",
                "Integrate automated tests into the CI/CD pipeline to ensure continuous validation of API quality.",
                "Implement deployment strategies (e.g., blue-green deployments, canary releases) to minimize risks during API releases.",
                "Establish a habit of reviewing metrics and planning continuous improvement activities."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            }
          ],
          "promptIds": [
            "partner-specialist:facilitate-station",
            "partner-specialist:use-resources",
            "partner-specialist:next-actions"
          ]
        },
        {
          "id": "platform-architect",
          "stakeholderId": "platform-architect",
          "title": "Platform Architect",
          "summary": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
          "stakeholder": {
            "id": "platform-architect",
            "sourceKey": "platform-architect",
            "sourceStakeholderId": "platform-architect",
            "title": "Platform Architect",
            "description": "Guides platform, integration, scalability, and architecture decisions that shape how the capability or API is built and operated.",
            "involvement": ""
          },
          "cycles": [
            {
              "id": "capability-productization-cycle",
              "title": "Capability Productization Cycle",
              "description": "A cycle for turning business capabilities into reusable digital capabilities before selecting the implementation style."
            },
            {
              "id": "api-productization-cycle",
              "title": "API Productization Cycle",
              "description": "The API-focused APIOps Cycles journey for productizing, designing, delivering, publishing, and improving APIs."
            },
            {
              "id": "integration-productization-cycle",
              "title": "Integration Productization Cycle",
              "description": "A cycle for productizing reusable integration capabilities before selecting the implementation style."
            },
            {
              "id": "automation-cycle",
              "title": "Automation Cycle",
              "description": "A cycle for identifying, designing, delivering, enabling, and improving automation opportunities."
            }
          ],
          "stations": [
            {
              "id": "api-product-strategy",
              "title": "Strategy",
              "description": "Frame the business need as a reusable capability before choosing the implementation style."
            },
            {
              "id": "api-platform-architecture",
              "title": "Architecture & Platform Decisions",
              "description": "Use requirements and constraints to decide the right architecture pattern and enabling platform capabilities."
            },
            {
              "id": "api-design",
              "title": "Solution & Interface Design",
              "description": "Design the interface contract and interaction model after the architecture choice is justified."
            },
            {
              "id": "api-delivery",
              "title": "Delivery & Operations",
              "description": "Deliver the selected implementation style with appropriate engineering, testing, security, automation, and operational practices."
            },
            {
              "id": "api-audit",
              "title": "Quality & Readiness Assurance",
              "description": "Audit the capability interface contract, controls, support model, observability, documentation, and lifecycle readiness before release."
            },
            {
              "id": "monitoring-and-improving",
              "title": "Monitoring & Improvement",
              "description": "Monitor usage, reliability, data quality, consumer outcomes, operational cost, and reuse opportunities after release."
            }
          ],
          "canvases": [
            {
              "id": "customerJourneyCanvas",
              "title": "Customer Journey Canvas"
            },
            {
              "id": "domainCanvas",
              "title": "Domain Canvas"
            },
            {
              "id": "capabilityValuePropositionCanvas",
              "title": "Capability Value Proposition Canvas"
            },
            {
              "id": "capabilityBusinessModelCanvas",
              "title": "Capability Business Model Canvas"
            },
            {
              "id": "businessImpactCanvas",
              "title": "Business Impact Canvas"
            },
            {
              "id": "locationsCanvas",
              "title": "Locations Canvas"
            },
            {
              "id": "capacityCanvas",
              "title": "Capacity Canvas"
            },
            {
              "id": "interactionCanvas",
              "title": "Interaction Canvas"
            },
            {
              "id": "apiValuePropositionCanvas",
              "title": "API Value Proposition Canvas"
            },
            {
              "id": "apiBusinessModelCanvas",
              "title": "API Business Model Canvas"
            },
            {
              "id": "restCanvas",
              "title": "REST Canvas"
            },
            {
              "id": "eventCanvas",
              "title": "Event Canvas"
            },
            {
              "id": "graphqlCanvas",
              "title": "GraphQL Canvas"
            }
          ],
          "decisions": [
            "Map the customer or partner journey that creates the capability need and reveals tasks, pains, gains, inputs, outputs, and decision points.",
            "Define the core entities, attributes, relationships, ownership, and business rules that the capability must respect.",
            "Use the Capability Value Proposition Canvas to capture consumer tasks, gains, pains, and reusable capability features without naming the delivery technology too early.",
            "Use the Capability Business Model Canvas to clarify ownership, partners, channels, costs, benefits, support, and lifecycle expectations for the reusable capability.",
            "Use shared journey, domain, value proposition, and business model canvases to gather technology-agnostic requirements and decide whether the capability should be reusable.",
            "Integration and API work often jumps too quickly to a technical pattern. This station keeps the team focused on the business journey, domain meaning, value, reuse potential, ownership, and viability before selecting APIs, events, files, streams, data products, or direct integration."
          ],
          "outputs": [
            "A technology-agnostic capability opportunity statement",
            "Shared understanding of consumers, producers, domain concepts, and reuse potential",
            "A capability value proposition and business model before architecture selection",
            "design-artifact",
            "documentation",
            "research",
            "roadmap",
            "A justified architecture choice"
          ],
          "recommendedResources": [
            {
              "id": "customerJourneyCanvas",
              "slug": "resources/customer-journey-canvas",
              "title": "Customer Journey Canvas",
              "description": "Map customer, partner, or consumer journeys to identify needs, pain points, gains, inputs, outputs, and experience expectations.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 1,
              "outcomes": [
                "Shared understanding of the customer, partner, or consumer journey",
                "Needs, pain points, gains, inputs, and outputs documented",
                "Journey evidence available for capability, requirements, and architecture decisions"
              ],
              "steps": [
                "Define customer persona",
                "Identify triggers for the journey",
                "Describe the journey's end",
                "Map journey steps with inputs/outputs",
                "Identify customer pains",
                "Summarize customer gains",
                "Define necessary inputs and resulting outputs",
                "Define interactions and processing expectations for each step"
              ],
              "canvasId": "customerJourneyCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "domainCanvas",
              "slug": "resources/domain-canvas",
              "title": "Domain Canvas",
              "description": "A modeling tool to define and communicate the key entities and relationships in your domain, ensuring semantic consistency across capabilities, integrations, APIs, data products, and services.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 152,
              "outcomes": [
                "Shared domain model and terminology",
                "Core entities, relationships, rules, and ownership clarified",
                "Semantic consistency across capabilities, integrations, APIs, data products, and services"
              ],
              "steps": [
                "Define core entities, their attributes, and relationships to create a shared conceptual understanding across capabilities, integrations, APIs, data products, and services."
              ],
              "canvasId": "domainCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capabilityValuePropositionCanvas",
              "slug": "resources/capability-value-proposition-canvas",
              "title": "Capability Value Proposition Canvas",
              "description": "A technology-agnostic canvas for mapping consumer tasks, gains, pains, and candidate reusable capabilities before selecting an implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 2.1,
              "outcomes": [
                "Clear reusable capability value proposition",
                "Consumer tasks, gains, and pains captured without assuming a technology",
                "Candidate reusable capabilities identified for architecture evaluation"
              ],
              "steps": [
                "List the consumer tasks and outcomes the capability should support.",
                "Identify gain-enabling capability features.",
                "Identify pain-relieving capability features.",
                "Group the features into candidate reusable capabilities."
              ],
              "canvasId": "capabilityValuePropositionCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capabilityBusinessModelCanvas",
              "slug": "resources/capability-business-model-canvas",
              "title": "Capability Business Model Canvas",
              "description": "A business model canvas for reusable capabilities, covering value, consumers, ownership, engagement, costs, and benefits without assuming an implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 3.1,
              "outcomes": [
                "Viable reusable capability operating model",
                "Ownership, consumers, channels, partners, and support needs clarified",
                "Costs and benefits visible before architecture commitment"
              ],
              "steps": [
                "Summarize the capability value proposition.",
                "Identify consumer segments and engagement channels.",
                "Define key activities, resources, and partners.",
                "Capture costs and benefits.",
                "Clarify ownership, funding, support, and lifecycle expectations.",
                "Validate the model with consumers, producers, and governance stakeholders."
              ],
              "canvasId": "capabilityBusinessModelCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "businessImpactCanvas",
              "slug": "resources/business-impact-canvas",
              "title": "Business Impact Canvas",
              "description": "Identify business, availability, security, data, compliance, and operational risks that should shape architecture and platform decisions.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 4,
              "outcomes": [
                "Documented business and operational impact assessment",
                "Prioritized risks and mitigation actions",
                "Evidence for architecture and platform decisions"
              ],
              "steps": [
                "Availability Risks: Identify risks and impacts.",
                "Ways to Mitigate Availability Risks: Define mitigation measures.",
                "Security Risks: Document security-related risks.",
                "Ways to Mitigate Security Risks: Propose strategies to mitigate security risks.",
                "Data Risks: Identify risks to data accuracy or availability.",
                "Ways to Mitigate Data Risks: Plan strategies to address data risks."
              ],
              "canvasId": "businessImpactCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "locationsCanvas",
              "slug": "resources/location-canvas",
              "title": "Location Canvas",
              "description": "Map consumer, producer, system, data, network, regulatory, and trust-boundary locations to ensure compliance and performance across regions.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 6,
              "outcomes": [
                "Documented location, residency, network, and regulatory requirements",
                "Regional performance and accessibility constraints identified",
                "Data residency, trust boundaries, and applicable regulations clarified"
              ],
              "steps": [
                "Map locations of producers, source systems, platforms, and consumers.",
                "Document where consumers are located.",
                "Identify applicable regulations.",
                "Document where data must reside.",
                "Ensure the capability is accessible in all intended network regions.",
                "Validate network performance across regions."
              ],
              "canvasId": "locationsCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capacityCanvas",
              "slug": "resources/capacity-canvas",
              "title": "Capacity Canvas",
              "description": "Plan capacity for current and future demand, including volumes, peaks, latency, availability, scaling, caching, and rate limits for the selected capability and implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 7,
              "outcomes": [
                "Capacity requirements aligned with expected business demand",
                "Peak-load, availability, and growth assumptions documented",
                "Scaling, caching, and rate-limiting decisions defined"
              ],
              "steps": [
                "Document current business volumes",
                "Forecast future consumption trends",
                "Plan for peak load and availability requirements",
                "Define caching and rate-limiting strategies",
                "Propose scaling strategies"
              ],
              "canvasId": "capacityCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "interactionCanvas",
              "slug": "resources/interaction-canvas",
              "title": "Interaction Canvas",
              "description": "Define interactions, workflows, inputs, outputs, commands, queries, events, and expected responses to ensure a consistent consumer experience.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 9,
              "outcomes": [
                "Defined interaction model for the selected capability",
                "Inputs, outputs, commands, queries, events, and responses clarified",
                "Validation rules and interaction expectations agreed"
              ],
              "steps": [
                "Map interactions to user, consumer, or system tasks",
                "Define access points, operations, commands, queries, or events for each interaction",
                "Document inputs and outputs for each interaction.",
                "Specify validation rules and constraints",
                "Create interaction models for CRUD, query-driven, command-driven, and event-driven interactions"
              ],
              "canvasId": "interactionCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "contract-first-design",
              "slug": "resources/contract-first-design",
              "title": "Contract First Design",
              "description": "A guideline advocating for API-first approaches using formal contracts (e.g., OpenAPI) to align stakeholders before development.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 146,
              "outcomes": [
                "Shared understanding of the purpose and use of Contract First Design",
                "A consistent approach to applying Contract First Design",
                "Improved application of the related practices"
              ],
              "steps": [
                "Apply contract-first or design-first approaches to ensure API interface contracts are validated before implementation.",
                "Define API interface contracts that outline the expectations, responsibilities, and usage guidelines for each API.",
                "Use standardized formats (e.g., OpenAPI, AsyncAPI) to create machine-readable API interface contracts that are easy to share and validate."
              ],
              "canvasId": null,
              "sourcePath": "src/snippets/api-contract-example.yaml",
              "sourceUrl": null,
              "contentMarkdown": "openapi: 3.0.3\r\ninfo:\r\n  title: Sample Catalog API\r\n  version: 1.0.0\r\n  description: |\r\n    Starter example for a read-only APIOps Cycles API.\r\n    This example keeps the contract audit-friendly and easy to extend.\r\nservers:\r\n  - url: /v1\r\n    description: Versioned API base path\r\ntags:\r\n  - name: catalog\r\n    description: Browse and search catalog items\r\npaths:\r\n  /items:\r\n    get:\r\n      tags: [catalog]\r\n      summary: List catalog items\r\n      description: Returns a paginated list of public catalog items.\r\n      operationId: listItems\r\n      parameters:\r\n        - $ref: \"#/components/parameters/searchTerm\"\r\n        - $ref: \"#/components/parameters/categoryId\"\r\n        - $ref: \"#/components/parameters/page\"\r\n        - $ref: \"#/components/parameters/pageSize\"\r\n      responses:\r\n        \"200\":\r\n          description: Item list\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemListResponse\"\r\n              examples:\r\n                default:\r\n                  value:\r\n                    data:\r\n                      - itemId: item-123\r\n                        slug: blue-widget\r\n                        name: Blue Widget\r\n                        status: published\r\n                    page:\r\n                      number: 1\r\n                      size: 20\r\n                      totalItems: 1\r\n        \"400\":\r\n          $ref: \"#/components/responses/BadRequest\"\r\n        \"429\":\r\n          $ref: \"#/components/responses/TooManyRequests\"\r\n  /items/{itemId}:\r\n    get:\r\n      tags: [catalog]\r\n      summary: Get item by id\r\n      description: Returns a single public catalog item by opaque identifier.\r\n      operationId: getItemById\r\n      parameters:\r\n        - $ref: \"#/components/parameters/itemId\"\r\n      responses:\r\n        \"200\":\r\n          description: Item details\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemDetail\"\r\n        \"400\":\r\n          $ref: \"#/components/responses/BadRequest\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\n  /items/by-slug/{slug}:\r\n    get:\r\n      tags: [catalog]\r\n      summary: Get item by slug\r\n      description: Returns a single item by public slug.\r\n      operationId: getItemBySlug\r\n      parameters:\r\n        - $ref: \"#/components/parameters/slug\"\r\n      responses:\r\n        \"200\":\r\n          description: Item details\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemDetail\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\n  /categories/{categoryId}/items:\r\n    get:\r\n      tags: [catalog]\r\n      summary: List items in category\r\n      description: Returns public items in a category.\r\n      operationId: listItemsByCategory\r\n      parameters:\r\n        - $ref: \"#/components/parameters/categoryId\"\r\n      responses:\r\n        \"200\":\r\n          description: Category item list\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemListResponse\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\ncomponents:\r\n  parameters:\r\n    itemId:\r\n      name: itemId\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9][a-z0-9-]{1,63}$\"\r\n      example: item-123\r\n    slug:\r\n      name: slug\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9]+(?:-[a-z0-9]+)*$\"\r\n      example: blue-widget\r\n    categoryId:\r\n      name: categoryId\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9][a-z0-9-]{1,63}$\"\r\n      example: home-goods\r\n    searchTerm:\r\n      name: searchTerm\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: string\r\n        minLength: 1\r\n      example: widget\r\n    page:\r\n      name: page\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: integer\r\n        minimum: 1\r\n        default: 1\r\n    pageSize:\r\n      name: pageSize\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: integer\r\n        minimum: 1\r\n        maximum: 100\r\n        default: 20\r\n  responses:\r\n    BadRequest:\r\n      description: Validation failed\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n          examples:\r\n            default:\r\n              value:\r\n                code: BAD_REQUEST\r\n                message: Invalid request\r\n    NotFound:\r\n      description: Resource not found\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n    TooManyRequests:\r\n      description: Rate limit exceeded\r\n      headers:\r\n        Retry-After:\r\n          schema:\r\n            type: integer\r\n          description: Seconds until the next allowed request.\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n  schemas:\r\n    ItemListResponse:\r\n      type: object\r\n      required: [data, page]\r\n      properties:\r\n        data:\r\n          type: array\r\n          items:\r\n            $ref: \"#/components/schemas/ItemSummary\"\r\n        page:\r\n          $ref: \"#/components/schemas/Page\"\r\n    ItemSummary:\r\n      type: object\r\n      required: [itemId, slug, name, status]\r\n      properties:\r\n        itemId:\r\n          type: string\r\n        slug:\r\n          type: string\r\n        name:\r\n          type: string\r\n        status:\r\n          type: string\r\n          enum: [published, hidden]\r\n    ItemDetail:\r\n      allOf:\r\n        - $ref: \"#/components/schemas/ItemSummary\"\r\n        - type: object\r\n          properties:\r\n            description:\r\n              type: string\r\n            categories:\r\n              type: array\r\n              items:\r\n                type: string\r\n            variants:\r\n              type: array\r\n              items:\r\n                $ref: \"#/components/schemas/Variant\"\r\n    Variant:\r\n      type: object\r\n      required: [variantId, sku, price, inventory]\r\n      properties:\r\n        variantId:\r\n          type: string\r\n        sku:\r\n          type: string\r\n        price:\r\n          $ref: \"#/components/schemas/Price\"\r\n        inventory:\r\n          $ref: \"#/components/schemas/Inventory\"\r\n    Price:\r\n      type: object\r\n      required: [amount, currency]\r\n      properties:\r\n        amount:\r\n          type: number\r\n          format: decimal\r\n        currency:\r\n          type: string\r\n          example: EUR\r\n    Inventory:\r\n      type: object\r\n      required: [available]\r\n      properties:\r\n        available:\r\n          type: integer\r\n          minimum: 0\r\n        reserved:\r\n          type: integer\r\n          minimum: 0\r\n        source:\r\n          type: string\r\n    Page:\r\n      type: object\r\n      required: [number, size, totalItems]\r\n      properties:\r\n        number:\r\n          type: integer\r\n        size:\r\n          type: integer\r\n        totalItems:\r\n          type: integer\r\n    ErrorResponse:\r\n      type: object\r\n      required: [code, message]\r\n      properties:\r\n        code:\r\n          type: string\r\n        message:\r\n          type: string\r\n",
              "draft": true
            },
            {
              "id": "api-development-best-practices",
              "slug": "resources/api-development-best-practices",
              "title": "API Development Best Practices",
              "description": "Implementation guidance for turning a validated API interface contract into a consistent, maintainable API codebase using standard libraries, reusable patterns, and aligned development workflows.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 112,
              "outcomes": [
                "Shared understanding of the purpose and use of API Development Best Practices",
                "A consistent approach to applying API Development Best Practices",
                "Improved application of the related practices"
              ],
              "steps": [
                "Apply these practices to the validated API interface contract and implementation plan before coding begins.",
                "Use established frameworks, libraries, and coding standards to implement the contract consistently and maintainably."
              ],
              "canvasId": null,
              "sourcePath": "src/snippets/api-design-principles-guidance.md",
              "sourceUrl": null,
              "contentMarkdown": "## How to start the API Delivery work based on the previous phases (\"stations\")\r\n\r\nUse this guidance at the start of `API Delivery` after the API contract (e.g. OpenAPI) and the key outputs from earlier stations have been reviewed and accepted.\r\n\r\nThe goal is not to invent implementation in isolation. The goal is to turn the agreed outputs from earlier stations into concrete code structure, validation rules, runtime behavior, and API product delivery decisions.\r\n\r\n---\r\n\r\n### 1. Start From The Validated Contract\r\n\r\n- Treat the validated API contract as the main reference point for implementation decisions.\r\n- Keep the contract and implementation aligned throughout the API product delivery.\r\n- Use the contract to drive request validation, response mapping, documentation, and tests.\r\n\r\n---\r\n\r\n### 2. Use Domain Outputs To Preserve Business Meaning\r\n\r\n- Use the `Domain Canvas` outputs to guide naming, how the implementation is split into clear business responsibilities, and how different backend systems are connected without exposing their differences.\r\n- Preserve the validated meanings of entities, attributes, statuses, and source-of-truth rules.\r\n- Avoid leaking backend-specific models or inconsistencies into the public API.\r\n\r\n---\r\n\r\n### 3. Use Journey Outputs To Preserve Critical Flows\r\n\r\n- Use the `Customer Journey Canvas` outputs to identify which user flows are most important to support first.\r\n- Use the `API Consumer Experience` outputs to keep the API understandable, predictable, and easy to integrate.\r\n- Let the agreed journey priorities decide which implementation paths need the highest reliability, lowest latency, clearest errors, and strongest operational focus.\r\n\r\n---\r\n\r\n### 4. Use Value Proposition Outputs To Preserve Consumer Value\r\n\r\n- Use the `API Value Proposition Canvas` outputs to keep the implementation focused on the agreed pains, gains, and API features.\r\n- Preserve the field meanings, behavior, and promises that made the API valuable in the earlier stations.\r\n- Ensure error handling, freshness, and naming support both the intended developer experience and the business use case.\r\n\r\n---\r\n\r\n### 5. Use Architecture Outputs To Shape Runtime Decisions\r\n\r\n- Use the `Business Impact Canvas` outputs to guide resilience, timeout, fallback, and degradation decisions.\r\n- Use the `Locations Canvas` outputs to guide network boundaries, trust boundaries, access paths, and deployment constraints.\r\n- Use the `Capacity Canvas` outputs to guide rate limits, caching, scaling, and peak-load behavior.\r\n- Use the `API Metrics And Analytics` guidance to decide what must be observed from the first implementation onward.\r\n\r\n---\r\n\r\n### 6. Use Interaction And Protocol Design Outputs To Shape Code Structure\r\n\r\n- Use the `Interaction Canvas` outputs to avoid implementing unsupported interaction styles too early.\r\n- Use the `REST`, `Event`, or `GraphQL` design outputs to shape protocol-specific request, response, and validation behavior.\r\n- Reflect the selected interaction style clearly in code structure, responsibilities, and testing strategy.\r\n\r\n---\r\n\r\n### 7. Use Audit Outputs To Improve Delivery Before Coding Goes Too Far\r\n\r\n- Use the audit findings to remove ambiguity before implementation spreads across the codebase.\r\n- Fix unclear request rules, missing validation, weak error contracts, and operational gaps early.\r\n- Treat audit as a design-improvement loop before production, not only as a final decision gate.\r\n\r\n---\r\n\r\n### 8. Apply The Guidance, Then Summarize\r\n\r\n- Apply this guidance to the current API and implementation plan.\r\n- Summarize the implications for code structure, request validation, source integration, security, monitoring and alerts, and testing.\r\n- Do not create a separate delivery artifact unless the team or user specifically needs one.\r\n",
              "draft": true
            }
          ],
          "promptIds": [
            "platform-architect:facilitate-station",
            "platform-architect:use-resources",
            "platform-architect:next-actions"
          ]
        },
        {
          "id": "platform-owner",
          "stakeholderId": "platform-owner",
          "title": "Platform Owner",
          "summary": "Owns platform capabilities, roadmap, operational model, and service expectations.",
          "stakeholder": {
            "id": "platform-owner",
            "sourceKey": "platform-owner",
            "sourceStakeholderId": "platform-owner",
            "title": "Platform Owner",
            "description": "Owns platform capabilities, roadmap, operational model, and service expectations.",
            "involvement": ""
          },
          "cycles": [
            {
              "id": "capability-productization-cycle",
              "title": "Capability Productization Cycle",
              "description": "A cycle for turning business capabilities into reusable digital capabilities before selecting the implementation style."
            },
            {
              "id": "integration-productization-cycle",
              "title": "Integration Productization Cycle",
              "description": "A cycle for productizing reusable integration capabilities before selecting the implementation style."
            },
            {
              "id": "automation-cycle",
              "title": "Automation Cycle",
              "description": "A cycle for identifying, designing, delivering, enabling, and improving automation opportunities."
            }
          ],
          "stations": [
            {
              "id": "api-platform-architecture",
              "title": "Architecture & Platform Decisions",
              "description": "Use requirements and constraints to decide the right architecture pattern and enabling platform capabilities."
            },
            {
              "id": "api-product-strategy",
              "title": "Strategy",
              "description": "Frame the business need as a reusable capability before choosing the implementation style."
            },
            {
              "id": "monitoring-and-improving",
              "title": "Monitoring & Improvement",
              "description": "Monitor usage, reliability, data quality, consumer outcomes, operational cost, and reuse opportunities after release."
            }
          ],
          "canvases": [
            {
              "id": "businessImpactCanvas",
              "title": "Business Impact Canvas"
            },
            {
              "id": "locationsCanvas",
              "title": "Locations Canvas"
            },
            {
              "id": "capacityCanvas",
              "title": "Capacity Canvas"
            },
            {
              "id": "customerJourneyCanvas",
              "title": "Customer Journey Canvas"
            },
            {
              "id": "domainCanvas",
              "title": "Domain Canvas"
            },
            {
              "id": "capabilityValuePropositionCanvas",
              "title": "Capability Value Proposition Canvas"
            },
            {
              "id": "capabilityBusinessModelCanvas",
              "title": "Capability Business Model Canvas"
            }
          ],
          "decisions": [
            "Use the Business Impact Canvas to identify availability, security, and data risks that influence architecture options.",
            "Use the Locations Canvas to capture geopolitical, regulatory, network, residency, and trust-boundary constraints.",
            "Use the Capacity Canvas to capture current and future volumes, peaks, latency, caching, rate limiting, and scaling expectations.",
            "Use metrics and analytics guidance to define how the chosen capability will be monitored and improved.",
            "Compare viable architecture styles against the gathered requirements and document the selected pattern and rationale.",
            "Architecture choices should follow from evidence about business impact, locations, trust boundaries, capacity, latency, data ownership, consistency, operability, security, privacy, governance, and cost."
          ],
          "outputs": [
            "A justified architecture choice",
            "Documented risks, locations, capacity, security, privacy, and operability constraints",
            "Clear rationale for API, event, file, stream, data product, direct integration, or hybrid implementation style",
            "architecture-decision",
            "documentation",
            "platform-config",
            "metrics",
            "A technology-agnostic capability opportunity statement"
          ],
          "recommendedResources": [
            {
              "id": "businessImpactCanvas",
              "slug": "resources/business-impact-canvas",
              "title": "Business Impact Canvas",
              "description": "Identify business, availability, security, data, compliance, and operational risks that should shape architecture and platform decisions.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 4,
              "outcomes": [
                "Documented business and operational impact assessment",
                "Prioritized risks and mitigation actions",
                "Evidence for architecture and platform decisions"
              ],
              "steps": [
                "Availability Risks: Identify risks and impacts.",
                "Ways to Mitigate Availability Risks: Define mitigation measures.",
                "Security Risks: Document security-related risks.",
                "Ways to Mitigate Security Risks: Propose strategies to mitigate security risks.",
                "Data Risks: Identify risks to data accuracy or availability.",
                "Ways to Mitigate Data Risks: Plan strategies to address data risks."
              ],
              "canvasId": "businessImpactCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "locationsCanvas",
              "slug": "resources/location-canvas",
              "title": "Location Canvas",
              "description": "Map consumer, producer, system, data, network, regulatory, and trust-boundary locations to ensure compliance and performance across regions.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 6,
              "outcomes": [
                "Documented location, residency, network, and regulatory requirements",
                "Regional performance and accessibility constraints identified",
                "Data residency, trust boundaries, and applicable regulations clarified"
              ],
              "steps": [
                "Map locations of producers, source systems, platforms, and consumers.",
                "Document where consumers are located.",
                "Identify applicable regulations.",
                "Document where data must reside.",
                "Ensure the capability is accessible in all intended network regions.",
                "Validate network performance across regions."
              ],
              "canvasId": "locationsCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capacityCanvas",
              "slug": "resources/capacity-canvas",
              "title": "Capacity Canvas",
              "description": "Plan capacity for current and future demand, including volumes, peaks, latency, availability, scaling, caching, and rate limits for the selected capability and implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 7,
              "outcomes": [
                "Capacity requirements aligned with expected business demand",
                "Peak-load, availability, and growth assumptions documented",
                "Scaling, caching, and rate-limiting decisions defined"
              ],
              "steps": [
                "Document current business volumes",
                "Forecast future consumption trends",
                "Plan for peak load and availability requirements",
                "Define caching and rate-limiting strategies",
                "Propose scaling strategies"
              ],
              "canvasId": "capacityCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "customerJourneyCanvas",
              "slug": "resources/customer-journey-canvas",
              "title": "Customer Journey Canvas",
              "description": "Map customer, partner, or consumer journeys to identify needs, pain points, gains, inputs, outputs, and experience expectations.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 1,
              "outcomes": [
                "Shared understanding of the customer, partner, or consumer journey",
                "Needs, pain points, gains, inputs, and outputs documented",
                "Journey evidence available for capability, requirements, and architecture decisions"
              ],
              "steps": [
                "Define customer persona",
                "Identify triggers for the journey",
                "Describe the journey's end",
                "Map journey steps with inputs/outputs",
                "Identify customer pains",
                "Summarize customer gains",
                "Define necessary inputs and resulting outputs",
                "Define interactions and processing expectations for each step"
              ],
              "canvasId": "customerJourneyCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "domainCanvas",
              "slug": "resources/domain-canvas",
              "title": "Domain Canvas",
              "description": "A modeling tool to define and communicate the key entities and relationships in your domain, ensuring semantic consistency across capabilities, integrations, APIs, data products, and services.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 152,
              "outcomes": [
                "Shared domain model and terminology",
                "Core entities, relationships, rules, and ownership clarified",
                "Semantic consistency across capabilities, integrations, APIs, data products, and services"
              ],
              "steps": [
                "Define core entities, their attributes, and relationships to create a shared conceptual understanding across capabilities, integrations, APIs, data products, and services."
              ],
              "canvasId": "domainCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capabilityValuePropositionCanvas",
              "slug": "resources/capability-value-proposition-canvas",
              "title": "Capability Value Proposition Canvas",
              "description": "A technology-agnostic canvas for mapping consumer tasks, gains, pains, and candidate reusable capabilities before selecting an implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 2.1,
              "outcomes": [
                "Clear reusable capability value proposition",
                "Consumer tasks, gains, and pains captured without assuming a technology",
                "Candidate reusable capabilities identified for architecture evaluation"
              ],
              "steps": [
                "List the consumer tasks and outcomes the capability should support.",
                "Identify gain-enabling capability features.",
                "Identify pain-relieving capability features.",
                "Group the features into candidate reusable capabilities."
              ],
              "canvasId": "capabilityValuePropositionCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capabilityBusinessModelCanvas",
              "slug": "resources/capability-business-model-canvas",
              "title": "Capability Business Model Canvas",
              "description": "A business model canvas for reusable capabilities, covering value, consumers, ownership, engagement, costs, and benefits without assuming an implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 3.1,
              "outcomes": [
                "Viable reusable capability operating model",
                "Ownership, consumers, channels, partners, and support needs clarified",
                "Costs and benefits visible before architecture commitment"
              ],
              "steps": [
                "Summarize the capability value proposition.",
                "Identify consumer segments and engagement channels.",
                "Define key activities, resources, and partners.",
                "Capture costs and benefits.",
                "Clarify ownership, funding, support, and lifecycle expectations.",
                "Validate the model with consumers, producers, and governance stakeholders."
              ],
              "canvasId": "capabilityBusinessModelCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "api-metrics-and-analytics",
              "slug": "resources/api-metrics-and-analytics",
              "title": "API Metrics And Analytics",
              "description": "A resource for defining, collecting, and analyzing API performance and usage data to align technical KPIs with business outcomes.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 119,
              "outcomes": [
                "Shared understanding of the purpose and use of API Metrics And Analytics",
                "A consistent approach to applying API Metrics And Analytics",
                "Improved application of the related practices"
              ],
              "steps": [
                "Identify key performance indicators (KPIs) to measure API success against business goals.",
                "Define and monitor performance metrics (e.g., API calls, latency, error rates) and adoption metrics (e.g., NPS).",
                "Monitor API initiatives to ensure adherence to operating guidelines and governance practices"
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "api-community-engagement-strategies",
              "slug": "resources/api-community-engagement-strategies",
              "title": "API Community Engagement Strategies",
              "description": "A playbook for fostering API adoption by cultivating communities through content, support channels, feedback loops, and social engagement strategies.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 103,
              "outcomes": [
                "Shared understanding of the purpose and use of API Community Engagement Strategies",
                "A consistent approach to applying API Community Engagement Strategies",
                "Improved application of the related practices"
              ],
              "steps": [
                "Develop marketing strategies to promote APIs to target audiences, including social media, blogs, and webinars.",
                "Create promotional materials (e.g., case studies, success stories) that highlight the value and benefits of APIs.",
                "Create educational materials (e.g., tutorials, documentation) that explain API features, benefits, and usage patterns.",
                "Engage with API consumers through feedback loops, support channels, and community forums to understand their needs and improve API adoption.",
                "Analyze API usage metrics and incorporate user feedback into API iterations."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "partner-integration-guidelines",
              "slug": "resources/partner-integration-guidelines",
              "title": "Partner Integration Guidelines",
              "description": "Integration checklists and communication patterns to manage technical and legal aspects of third-party API relationships.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 164,
              "outcomes": [
                "Shared understanding of the purpose and use of Partner Integration Guidelines",
                "A consistent approach to applying Partner Integration Guidelines",
                "Improved application of the related practices"
              ],
              "steps": [
                "Establish integration processes and guidelines for collaborating with partners, including technical integration, data sharing, and support.",
                "Monitor partner API performance and compliance to ensure reliability and alignment with your API strategy."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            }
          ],
          "promptIds": [
            "platform-owner:facilitate-station",
            "platform-owner:use-resources",
            "platform-owner:next-actions"
          ]
        },
        {
          "id": "process-owner",
          "stakeholderId": "process-owner",
          "title": "Process Owner",
          "summary": "Owns the business process being automated, including objectives, rules, outcomes, and improvement priorities.",
          "stakeholder": {
            "id": "process-owner",
            "sourceKey": "process-owner",
            "sourceStakeholderId": "process-owner",
            "title": "Process Owner",
            "description": "Owns the business process being automated, including objectives, rules, outcomes, and improvement priorities.",
            "involvement": ""
          },
          "cycles": [
            {
              "id": "automation-cycle",
              "title": "Automation Cycle",
              "description": "A cycle for identifying, designing, delivering, enabling, and improving automation opportunities."
            }
          ],
          "stations": [
            {
              "id": "api-product-strategy",
              "title": "Strategy",
              "description": "Frame the business need as a reusable capability before choosing the implementation style."
            },
            {
              "id": "api-consumer-experience",
              "title": "Consumer Requirements & Onboarding",
              "description": "Capture consumer onboarding, standards, non-functional requirements, service expectations, constraints, security needs, allowed protocols, data freshness, SLAs, observability, recovery, adoption requirements, and producer responsibilities."
            },
            {
              "id": "api-design",
              "title": "Solution & Interface Design",
              "description": "Design the interface contract and interaction model after the architecture choice is justified."
            },
            {
              "id": "api-delivery",
              "title": "Delivery & Operations",
              "description": "Deliver the selected implementation style with appropriate engineering, testing, security, automation, and operational practices."
            },
            {
              "id": "api-audit",
              "title": "Quality & Readiness Assurance",
              "description": "Audit the capability interface contract, controls, support model, observability, documentation, and lifecycle readiness before release."
            },
            {
              "id": "api-publishing",
              "title": "Publishing & Enablement",
              "description": "Publish reusable capability information so consumers can discover, request, onboard, use, and get support."
            },
            {
              "id": "monitoring-and-improving",
              "title": "Monitoring & Improvement",
              "description": "Monitor usage, reliability, data quality, consumer outcomes, operational cost, and reuse opportunities after release."
            }
          ],
          "canvases": [
            {
              "id": "customerJourneyCanvas",
              "title": "Customer Journey Canvas"
            },
            {
              "id": "domainCanvas",
              "title": "Domain Canvas"
            },
            {
              "id": "capabilityValuePropositionCanvas",
              "title": "Capability Value Proposition Canvas"
            },
            {
              "id": "consumerExperienceRequirementsCanvas",
              "title": "Consumer Experience Requirements Canvas"
            },
            {
              "id": "interactionCanvas",
              "title": "Interaction Canvas"
            }
          ],
          "decisions": [
            "Map the customer or partner journey that creates the capability need and reveals tasks, pains, gains, inputs, outputs, and decision points.",
            "Define the core entities, attributes, relationships, ownership, and business rules that the capability must respect.",
            "Use the Capability Value Proposition Canvas to capture consumer tasks, gains, pains, and reusable capability features without naming the delivery technology too early.",
            "Use the Capability Business Model Canvas to clarify ownership, partners, channels, costs, benefits, support, and lifecycle expectations for the reusable capability.",
            "Use shared journey, domain, value proposition, and business model canvases to gather technology-agnostic requirements and decide whether the capability should be reusable.",
            "Integration and API work often jumps too quickly to a technical pattern. This station keeps the team focused on the business journey, domain meaning, value, reuse potential, ownership, and viability before selecting APIs, events, files, streams, data products, or direct integration."
          ],
          "outputs": [
            "A technology-agnostic capability opportunity statement",
            "Shared understanding of consumers, producers, domain concepts, and reuse potential",
            "A capability value proposition and business model before architecture selection",
            "design-artifact",
            "documentation",
            "research",
            "roadmap",
            "Documented consumer requirements and onboarding expectations"
          ],
          "recommendedResources": [
            {
              "id": "customerJourneyCanvas",
              "slug": "resources/customer-journey-canvas",
              "title": "Customer Journey Canvas",
              "description": "Map customer, partner, or consumer journeys to identify needs, pain points, gains, inputs, outputs, and experience expectations.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 1,
              "outcomes": [
                "Shared understanding of the customer, partner, or consumer journey",
                "Needs, pain points, gains, inputs, and outputs documented",
                "Journey evidence available for capability, requirements, and architecture decisions"
              ],
              "steps": [
                "Define customer persona",
                "Identify triggers for the journey",
                "Describe the journey's end",
                "Map journey steps with inputs/outputs",
                "Identify customer pains",
                "Summarize customer gains",
                "Define necessary inputs and resulting outputs",
                "Define interactions and processing expectations for each step"
              ],
              "canvasId": "customerJourneyCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "domainCanvas",
              "slug": "resources/domain-canvas",
              "title": "Domain Canvas",
              "description": "A modeling tool to define and communicate the key entities and relationships in your domain, ensuring semantic consistency across capabilities, integrations, APIs, data products, and services.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 152,
              "outcomes": [
                "Shared domain model and terminology",
                "Core entities, relationships, rules, and ownership clarified",
                "Semantic consistency across capabilities, integrations, APIs, data products, and services"
              ],
              "steps": [
                "Define core entities, their attributes, and relationships to create a shared conceptual understanding across capabilities, integrations, APIs, data products, and services."
              ],
              "canvasId": "domainCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capabilityValuePropositionCanvas",
              "slug": "resources/capability-value-proposition-canvas",
              "title": "Capability Value Proposition Canvas",
              "description": "A technology-agnostic canvas for mapping consumer tasks, gains, pains, and candidate reusable capabilities before selecting an implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 2.1,
              "outcomes": [
                "Clear reusable capability value proposition",
                "Consumer tasks, gains, and pains captured without assuming a technology",
                "Candidate reusable capabilities identified for architecture evaluation"
              ],
              "steps": [
                "List the consumer tasks and outcomes the capability should support.",
                "Identify gain-enabling capability features.",
                "Identify pain-relieving capability features.",
                "Group the features into candidate reusable capabilities."
              ],
              "canvasId": "capabilityValuePropositionCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "consumerExperienceRequirementsCanvas",
              "slug": "resources/consumer-experience-requirements-canvas",
              "title": "Consumer Experience Requirements Canvas",
              "description": "A requirements canvas for consumer experience and non-functional needs that should guide the later architecture and implementation-style decision.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 3.2,
              "outcomes": [
                "Technology-agnostic consumer and service requirements",
                "Experience and non-functional needs captured before design starts",
                "Architecture implications documented for implementation-style selection"
              ],
              "steps": [
                "Capture consumer goals and usage context.",
                "Document availability, timeliness, volume, performance, data quality, and consistency expectations.",
                "Document security, privacy, onboarding, change, observability, support, and recovery expectations.",
                "Summarize what the requirements imply for possible implementation styles."
              ],
              "canvasId": "consumerExperienceRequirementsCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "interactionCanvas",
              "slug": "resources/interaction-canvas",
              "title": "Interaction Canvas",
              "description": "Define interactions, workflows, inputs, outputs, commands, queries, events, and expected responses to ensure a consistent consumer experience.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 9,
              "outcomes": [
                "Defined interaction model for the selected capability",
                "Inputs, outputs, commands, queries, events, and responses clarified",
                "Validation rules and interaction expectations agreed"
              ],
              "steps": [
                "Map interactions to user, consumer, or system tasks",
                "Define access points, operations, commands, queries, or events for each interaction",
                "Document inputs and outputs for each interaction.",
                "Specify validation rules and constraints",
                "Create interaction models for CRUD, query-driven, command-driven, and event-driven interactions"
              ],
              "canvasId": "interactionCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "process-workflow-design-guide",
              "slug": "resources/process-workflow-design-guide",
              "title": "Process Workflow Design Guide",
              "description": "Guidance for modeling the process steps, roles, handoffs, decision points, states, inputs, outputs, and exceptions that shape an automation workflow.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 181,
              "outcomes": [
                "Clear automation workflow design",
                "Process steps and handoffs documented before implementation",
                "Workflow states, inputs, outputs, and exception paths understood"
              ],
              "steps": [
                "Map the current and target process flow, including human and system responsibilities.",
                "Identify workflow triggers, states, decisions, data inputs, outputs, and completion criteria.",
                "Document handoffs between users, systems, operations, and support roles.",
                "Confirm which steps should be automated and which require human judgment."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "decision-business-rules-guide",
              "slug": "resources/decision-business-rules-guide",
              "title": "Decision And Business Rules Guide",
              "description": "Guidance for capturing rules, thresholds, decisions, approvals, eligibility checks, and rule ownership for automation design.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 182,
              "outcomes": [
                "Explicit decisions and business rules",
                "Rules and thresholds documented with owners",
                "Automation decisions traceable to policy, process, or business intent"
              ],
              "steps": [
                "List decisions the automation must make or support.",
                "Document rule conditions, thresholds, exceptions, approvals, and escalation points.",
                "Identify rule owners and change governance for each decision area."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "automation-trigger-handoff-exception-guide",
              "slug": "resources/automation-trigger-handoff-exception-guide",
              "title": "Automation Trigger, Handoff And Exception Guide",
              "description": "Guidance for defining automation triggers, human handoffs, exception handling, retries, compensating actions, and support escalation paths.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 183,
              "outcomes": [
                "Defined automation triggers and exception paths",
                "Human handoffs and support escalations are explicit",
                "Exceptions, retries, and compensating actions are designed before delivery"
              ],
              "steps": [
                "Define the events, schedules, user actions, or system states that trigger the automation.",
                "Map handoffs from automation to users, operators, or support teams.",
                "Document exceptions, retry rules, timeout behavior, and fallback paths.",
                "Define alerts and escalation thresholds for failed or ambiguous automation outcomes."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "automation-testing-guide",
              "slug": "resources/automation-testing-guide",
              "title": "Automation Testing Guide",
              "description": "Guidance for testing automated workflows, decisions, integrations, exceptions, rollback behavior, supervision, and user impact before release.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 184,
              "outcomes": [
                "Validated automation behavior",
                "Workflow, rule, exception, and integration tests defined",
                "Release confidence for automated and human-assisted paths"
              ],
              "steps": [
                "Create tests for happy paths, edge cases, exceptions, retries, and handoffs.",
                "Validate business rules and decision outcomes with representative data.",
                "Test rollback, recovery, observability, and manual intervention paths.",
                "Include users and operators in acceptance testing where the automation changes work practices."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "automation-operational-ownership-guide",
              "slug": "resources/automation-operational-ownership-guide",
              "title": "Automation Operational Ownership Guide",
              "description": "Guidance for defining ownership, runbooks, supervision, support, monitoring, change control, and continuous improvement responsibilities for automations.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 185,
              "outcomes": [
                "Clear automation operating model",
                "Ownership, support, and escalation responsibilities assigned",
                "Monitoring and change practices ready for live operation"
              ],
              "steps": [
                "Define business, technical, and operational owners for the automation.",
                "Document runbooks, support paths, monitoring signals, service expectations, and escalation rules.",
                "Set change control and review practices for workflow, platform, and rule updates."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            }
          ],
          "promptIds": [
            "process-owner:facilitate-station",
            "process-owner:use-resources",
            "process-owner:next-actions"
          ]
        },
        {
          "id": "security-specialist",
          "stakeholderId": "security-specialist",
          "title": "Security Specialist",
          "summary": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
          "stakeholder": {
            "id": "security-specialist",
            "sourceKey": "security-specialist",
            "sourceStakeholderId": "security-specialist",
            "title": "Security Specialist",
            "description": "Ensures security risks, controls, and trust boundaries are addressed throughout the API lifecycle.",
            "involvement": ""
          },
          "cycles": [
            {
              "id": "capability-productization-cycle",
              "title": "Capability Productization Cycle",
              "description": "A cycle for turning business capabilities into reusable digital capabilities before selecting the implementation style."
            },
            {
              "id": "api-productization-cycle",
              "title": "API Productization Cycle",
              "description": "The API-focused APIOps Cycles journey for productizing, designing, delivering, publishing, and improving APIs."
            },
            {
              "id": "integration-productization-cycle",
              "title": "Integration Productization Cycle",
              "description": "A cycle for productizing reusable integration capabilities before selecting the implementation style."
            },
            {
              "id": "automation-cycle",
              "title": "Automation Cycle",
              "description": "A cycle for identifying, designing, delivering, enabling, and improving automation opportunities."
            }
          ],
          "stations": [
            {
              "id": "api-platform-architecture",
              "title": "Architecture & Platform Decisions",
              "description": "Use requirements and constraints to decide the right architecture pattern and enabling platform capabilities."
            },
            {
              "id": "api-design",
              "title": "Solution & Interface Design",
              "description": "Design the interface contract and interaction model after the architecture choice is justified."
            },
            {
              "id": "api-delivery",
              "title": "Delivery & Operations",
              "description": "Deliver the selected implementation style with appropriate engineering, testing, security, automation, and operational practices."
            },
            {
              "id": "api-audit",
              "title": "Quality & Readiness Assurance",
              "description": "Audit the capability interface contract, controls, support model, observability, documentation, and lifecycle readiness before release."
            },
            {
              "id": "api-publishing",
              "title": "Publishing & Enablement",
              "description": "Publish reusable capability information so consumers can discover, request, onboard, use, and get support."
            },
            {
              "id": "monitoring-and-improving",
              "title": "Monitoring & Improvement",
              "description": "Monitor usage, reliability, data quality, consumer outcomes, operational cost, and reuse opportunities after release."
            },
            {
              "id": "api-product-strategy",
              "title": "Strategy",
              "description": "Frame the business need as a reusable capability before choosing the implementation style."
            }
          ],
          "canvases": [
            {
              "id": "businessImpactCanvas",
              "title": "Business Impact Canvas"
            },
            {
              "id": "locationsCanvas",
              "title": "Locations Canvas"
            },
            {
              "id": "capacityCanvas",
              "title": "Capacity Canvas"
            },
            {
              "id": "domainCanvas",
              "title": "Domain Canvas"
            },
            {
              "id": "interactionCanvas",
              "title": "Interaction Canvas"
            },
            {
              "id": "customerJourneyCanvas",
              "title": "Customer Journey Canvas"
            },
            {
              "id": "capabilityValuePropositionCanvas",
              "title": "Capability Value Proposition Canvas"
            },
            {
              "id": "capabilityBusinessModelCanvas",
              "title": "Capability Business Model Canvas"
            },
            {
              "id": "restCanvas",
              "title": "REST Canvas"
            },
            {
              "id": "eventCanvas",
              "title": "Event Canvas"
            },
            {
              "id": "graphqlCanvas",
              "title": "GraphQL Canvas"
            },
            {
              "id": "apiValuePropositionCanvas",
              "title": "API Value Proposition Canvas"
            },
            {
              "id": "apiBusinessModelCanvas",
              "title": "API Business Model Canvas"
            }
          ],
          "decisions": [
            "Use the Business Impact Canvas to identify availability, security, and data risks that influence architecture options.",
            "Use the Locations Canvas to capture geopolitical, regulatory, network, residency, and trust-boundary constraints.",
            "Use the Capacity Canvas to capture current and future volumes, peaks, latency, caching, rate limiting, and scaling expectations.",
            "Use metrics and analytics guidance to define how the chosen capability will be monitored and improved.",
            "Compare viable architecture styles against the gathered requirements and document the selected pattern and rationale.",
            "Architecture choices should follow from evidence about business impact, locations, trust boundaries, capacity, latency, data ownership, consistency, operability, security, privacy, governance, and cost."
          ],
          "outputs": [
            "A justified architecture choice",
            "Documented risks, locations, capacity, security, privacy, and operability constraints",
            "Clear rationale for API, event, file, stream, data product, direct integration, or hybrid implementation style",
            "architecture-decision",
            "documentation",
            "platform-config",
            "metrics",
            "A validated interface contract for the selected implementation style"
          ],
          "recommendedResources": [
            {
              "id": "businessImpactCanvas",
              "slug": "resources/business-impact-canvas",
              "title": "Business Impact Canvas",
              "description": "Identify business, availability, security, data, compliance, and operational risks that should shape architecture and platform decisions.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 4,
              "outcomes": [
                "Documented business and operational impact assessment",
                "Prioritized risks and mitigation actions",
                "Evidence for architecture and platform decisions"
              ],
              "steps": [
                "Availability Risks: Identify risks and impacts.",
                "Ways to Mitigate Availability Risks: Define mitigation measures.",
                "Security Risks: Document security-related risks.",
                "Ways to Mitigate Security Risks: Propose strategies to mitigate security risks.",
                "Data Risks: Identify risks to data accuracy or availability.",
                "Ways to Mitigate Data Risks: Plan strategies to address data risks."
              ],
              "canvasId": "businessImpactCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "locationsCanvas",
              "slug": "resources/location-canvas",
              "title": "Location Canvas",
              "description": "Map consumer, producer, system, data, network, regulatory, and trust-boundary locations to ensure compliance and performance across regions.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 6,
              "outcomes": [
                "Documented location, residency, network, and regulatory requirements",
                "Regional performance and accessibility constraints identified",
                "Data residency, trust boundaries, and applicable regulations clarified"
              ],
              "steps": [
                "Map locations of producers, source systems, platforms, and consumers.",
                "Document where consumers are located.",
                "Identify applicable regulations.",
                "Document where data must reside.",
                "Ensure the capability is accessible in all intended network regions.",
                "Validate network performance across regions."
              ],
              "canvasId": "locationsCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "capacityCanvas",
              "slug": "resources/capacity-canvas",
              "title": "Capacity Canvas",
              "description": "Plan capacity for current and future demand, including volumes, peaks, latency, availability, scaling, caching, and rate limits for the selected capability and implementation style.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 7,
              "outcomes": [
                "Capacity requirements aligned with expected business demand",
                "Peak-load, availability, and growth assumptions documented",
                "Scaling, caching, and rate-limiting decisions defined"
              ],
              "steps": [
                "Document current business volumes",
                "Forecast future consumption trends",
                "Plan for peak load and availability requirements",
                "Define caching and rate-limiting strategies",
                "Propose scaling strategies"
              ],
              "canvasId": "capacityCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "domainCanvas",
              "slug": "resources/domain-canvas",
              "title": "Domain Canvas",
              "description": "A modeling tool to define and communicate the key entities and relationships in your domain, ensuring semantic consistency across capabilities, integrations, APIs, data products, and services.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 152,
              "outcomes": [
                "Shared domain model and terminology",
                "Core entities, relationships, rules, and ownership clarified",
                "Semantic consistency across capabilities, integrations, APIs, data products, and services"
              ],
              "steps": [
                "Define core entities, their attributes, and relationships to create a shared conceptual understanding across capabilities, integrations, APIs, data products, and services."
              ],
              "canvasId": "domainCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "interactionCanvas",
              "slug": "resources/interaction-canvas",
              "title": "Interaction Canvas",
              "description": "Define interactions, workflows, inputs, outputs, commands, queries, events, and expected responses to ensure a consistent consumer experience.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 9,
              "outcomes": [
                "Defined interaction model for the selected capability",
                "Inputs, outputs, commands, queries, events, and responses clarified",
                "Validation rules and interaction expectations agreed"
              ],
              "steps": [
                "Map interactions to user, consumer, or system tasks",
                "Define access points, operations, commands, queries, or events for each interaction",
                "Document inputs and outputs for each interaction.",
                "Specify validation rules and constraints",
                "Create interaction models for CRUD, query-driven, command-driven, and event-driven interactions"
              ],
              "canvasId": "interactionCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "contract-first-design",
              "slug": "resources/contract-first-design",
              "title": "Contract First Design",
              "description": "A guideline advocating for API-first approaches using formal contracts (e.g., OpenAPI) to align stakeholders before development.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 146,
              "outcomes": [
                "Shared understanding of the purpose and use of Contract First Design",
                "A consistent approach to applying Contract First Design",
                "Improved application of the related practices"
              ],
              "steps": [
                "Apply contract-first or design-first approaches to ensure API interface contracts are validated before implementation.",
                "Define API interface contracts that outline the expectations, responsibilities, and usage guidelines for each API.",
                "Use standardized formats (e.g., OpenAPI, AsyncAPI) to create machine-readable API interface contracts that are easy to share and validate."
              ],
              "canvasId": null,
              "sourcePath": "src/snippets/api-contract-example.yaml",
              "sourceUrl": null,
              "contentMarkdown": "openapi: 3.0.3\r\ninfo:\r\n  title: Sample Catalog API\r\n  version: 1.0.0\r\n  description: |\r\n    Starter example for a read-only APIOps Cycles API.\r\n    This example keeps the contract audit-friendly and easy to extend.\r\nservers:\r\n  - url: /v1\r\n    description: Versioned API base path\r\ntags:\r\n  - name: catalog\r\n    description: Browse and search catalog items\r\npaths:\r\n  /items:\r\n    get:\r\n      tags: [catalog]\r\n      summary: List catalog items\r\n      description: Returns a paginated list of public catalog items.\r\n      operationId: listItems\r\n      parameters:\r\n        - $ref: \"#/components/parameters/searchTerm\"\r\n        - $ref: \"#/components/parameters/categoryId\"\r\n        - $ref: \"#/components/parameters/page\"\r\n        - $ref: \"#/components/parameters/pageSize\"\r\n      responses:\r\n        \"200\":\r\n          description: Item list\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemListResponse\"\r\n              examples:\r\n                default:\r\n                  value:\r\n                    data:\r\n                      - itemId: item-123\r\n                        slug: blue-widget\r\n                        name: Blue Widget\r\n                        status: published\r\n                    page:\r\n                      number: 1\r\n                      size: 20\r\n                      totalItems: 1\r\n        \"400\":\r\n          $ref: \"#/components/responses/BadRequest\"\r\n        \"429\":\r\n          $ref: \"#/components/responses/TooManyRequests\"\r\n  /items/{itemId}:\r\n    get:\r\n      tags: [catalog]\r\n      summary: Get item by id\r\n      description: Returns a single public catalog item by opaque identifier.\r\n      operationId: getItemById\r\n      parameters:\r\n        - $ref: \"#/components/parameters/itemId\"\r\n      responses:\r\n        \"200\":\r\n          description: Item details\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemDetail\"\r\n        \"400\":\r\n          $ref: \"#/components/responses/BadRequest\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\n  /items/by-slug/{slug}:\r\n    get:\r\n      tags: [catalog]\r\n      summary: Get item by slug\r\n      description: Returns a single item by public slug.\r\n      operationId: getItemBySlug\r\n      parameters:\r\n        - $ref: \"#/components/parameters/slug\"\r\n      responses:\r\n        \"200\":\r\n          description: Item details\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemDetail\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\n  /categories/{categoryId}/items:\r\n    get:\r\n      tags: [catalog]\r\n      summary: List items in category\r\n      description: Returns public items in a category.\r\n      operationId: listItemsByCategory\r\n      parameters:\r\n        - $ref: \"#/components/parameters/categoryId\"\r\n      responses:\r\n        \"200\":\r\n          description: Category item list\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemListResponse\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\ncomponents:\r\n  parameters:\r\n    itemId:\r\n      name: itemId\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9][a-z0-9-]{1,63}$\"\r\n      example: item-123\r\n    slug:\r\n      name: slug\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9]+(?:-[a-z0-9]+)*$\"\r\n      example: blue-widget\r\n    categoryId:\r\n      name: categoryId\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9][a-z0-9-]{1,63}$\"\r\n      example: home-goods\r\n    searchTerm:\r\n      name: searchTerm\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: string\r\n        minLength: 1\r\n      example: widget\r\n    page:\r\n      name: page\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: integer\r\n        minimum: 1\r\n        default: 1\r\n    pageSize:\r\n      name: pageSize\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: integer\r\n        minimum: 1\r\n        maximum: 100\r\n        default: 20\r\n  responses:\r\n    BadRequest:\r\n      description: Validation failed\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n          examples:\r\n            default:\r\n              value:\r\n                code: BAD_REQUEST\r\n                message: Invalid request\r\n    NotFound:\r\n      description: Resource not found\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n    TooManyRequests:\r\n      description: Rate limit exceeded\r\n      headers:\r\n        Retry-After:\r\n          schema:\r\n            type: integer\r\n          description: Seconds until the next allowed request.\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n  schemas:\r\n    ItemListResponse:\r\n      type: object\r\n      required: [data, page]\r\n      properties:\r\n        data:\r\n          type: array\r\n          items:\r\n            $ref: \"#/components/schemas/ItemSummary\"\r\n        page:\r\n          $ref: \"#/components/schemas/Page\"\r\n    ItemSummary:\r\n      type: object\r\n      required: [itemId, slug, name, status]\r\n      properties:\r\n        itemId:\r\n          type: string\r\n        slug:\r\n          type: string\r\n        name:\r\n          type: string\r\n        status:\r\n          type: string\r\n          enum: [published, hidden]\r\n    ItemDetail:\r\n      allOf:\r\n        - $ref: \"#/components/schemas/ItemSummary\"\r\n        - type: object\r\n          properties:\r\n            description:\r\n              type: string\r\n            categories:\r\n              type: array\r\n              items:\r\n                type: string\r\n            variants:\r\n              type: array\r\n              items:\r\n                $ref: \"#/components/schemas/Variant\"\r\n    Variant:\r\n      type: object\r\n      required: [variantId, sku, price, inventory]\r\n      properties:\r\n        variantId:\r\n          type: string\r\n        sku:\r\n          type: string\r\n        price:\r\n          $ref: \"#/components/schemas/Price\"\r\n        inventory:\r\n          $ref: \"#/components/schemas/Inventory\"\r\n    Price:\r\n      type: object\r\n      required: [amount, currency]\r\n      properties:\r\n        amount:\r\n          type: number\r\n          format: decimal\r\n        currency:\r\n          type: string\r\n          example: EUR\r\n    Inventory:\r\n      type: object\r\n      required: [available]\r\n      properties:\r\n        available:\r\n          type: integer\r\n          minimum: 0\r\n        reserved:\r\n          type: integer\r\n          minimum: 0\r\n        source:\r\n          type: string\r\n    Page:\r\n      type: object\r\n      required: [number, size, totalItems]\r\n      properties:\r\n        number:\r\n          type: integer\r\n        size:\r\n          type: integer\r\n        totalItems:\r\n          type: integer\r\n    ErrorResponse:\r\n      type: object\r\n      required: [code, message]\r\n      properties:\r\n        code:\r\n          type: string\r\n        message:\r\n          type: string\r\n",
              "draft": true
            },
            {
              "id": "api-development-best-practices",
              "slug": "resources/api-development-best-practices",
              "title": "API Development Best Practices",
              "description": "Implementation guidance for turning a validated API interface contract into a consistent, maintainable API codebase using standard libraries, reusable patterns, and aligned development workflows.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 112,
              "outcomes": [
                "Shared understanding of the purpose and use of API Development Best Practices",
                "A consistent approach to applying API Development Best Practices",
                "Improved application of the related practices"
              ],
              "steps": [
                "Apply these practices to the validated API interface contract and implementation plan before coding begins.",
                "Use established frameworks, libraries, and coding standards to implement the contract consistently and maintainably."
              ],
              "canvasId": null,
              "sourcePath": "src/snippets/api-design-principles-guidance.md",
              "sourceUrl": null,
              "contentMarkdown": "## How to start the API Delivery work based on the previous phases (\"stations\")\r\n\r\nUse this guidance at the start of `API Delivery` after the API contract (e.g. OpenAPI) and the key outputs from earlier stations have been reviewed and accepted.\r\n\r\nThe goal is not to invent implementation in isolation. The goal is to turn the agreed outputs from earlier stations into concrete code structure, validation rules, runtime behavior, and API product delivery decisions.\r\n\r\n---\r\n\r\n### 1. Start From The Validated Contract\r\n\r\n- Treat the validated API contract as the main reference point for implementation decisions.\r\n- Keep the contract and implementation aligned throughout the API product delivery.\r\n- Use the contract to drive request validation, response mapping, documentation, and tests.\r\n\r\n---\r\n\r\n### 2. Use Domain Outputs To Preserve Business Meaning\r\n\r\n- Use the `Domain Canvas` outputs to guide naming, how the implementation is split into clear business responsibilities, and how different backend systems are connected without exposing their differences.\r\n- Preserve the validated meanings of entities, attributes, statuses, and source-of-truth rules.\r\n- Avoid leaking backend-specific models or inconsistencies into the public API.\r\n\r\n---\r\n\r\n### 3. Use Journey Outputs To Preserve Critical Flows\r\n\r\n- Use the `Customer Journey Canvas` outputs to identify which user flows are most important to support first.\r\n- Use the `API Consumer Experience` outputs to keep the API understandable, predictable, and easy to integrate.\r\n- Let the agreed journey priorities decide which implementation paths need the highest reliability, lowest latency, clearest errors, and strongest operational focus.\r\n\r\n---\r\n\r\n### 4. Use Value Proposition Outputs To Preserve Consumer Value\r\n\r\n- Use the `API Value Proposition Canvas` outputs to keep the implementation focused on the agreed pains, gains, and API features.\r\n- Preserve the field meanings, behavior, and promises that made the API valuable in the earlier stations.\r\n- Ensure error handling, freshness, and naming support both the intended developer experience and the business use case.\r\n\r\n---\r\n\r\n### 5. Use Architecture Outputs To Shape Runtime Decisions\r\n\r\n- Use the `Business Impact Canvas` outputs to guide resilience, timeout, fallback, and degradation decisions.\r\n- Use the `Locations Canvas` outputs to guide network boundaries, trust boundaries, access paths, and deployment constraints.\r\n- Use the `Capacity Canvas` outputs to guide rate limits, caching, scaling, and peak-load behavior.\r\n- Use the `API Metrics And Analytics` guidance to decide what must be observed from the first implementation onward.\r\n\r\n---\r\n\r\n### 6. Use Interaction And Protocol Design Outputs To Shape Code Structure\r\n\r\n- Use the `Interaction Canvas` outputs to avoid implementing unsupported interaction styles too early.\r\n- Use the `REST`, `Event`, or `GraphQL` design outputs to shape protocol-specific request, response, and validation behavior.\r\n- Reflect the selected interaction style clearly in code structure, responsibilities, and testing strategy.\r\n\r\n---\r\n\r\n### 7. Use Audit Outputs To Improve Delivery Before Coding Goes Too Far\r\n\r\n- Use the audit findings to remove ambiguity before implementation spreads across the codebase.\r\n- Fix unclear request rules, missing validation, weak error contracts, and operational gaps early.\r\n- Treat audit as a design-improvement loop before production, not only as a final decision gate.\r\n\r\n---\r\n\r\n### 8. Apply The Guidance, Then Summarize\r\n\r\n- Apply this guidance to the current API and implementation plan.\r\n- Summarize the implications for code structure, request validation, source integration, security, monitoring and alerts, and testing.\r\n- Do not create a separate delivery artifact unless the team or user specifically needs one.\r\n",
              "draft": true
            },
            {
              "id": "api-testing-best-practices",
              "slug": "resources/api-testing-best-practices",
              "title": "API Testing Best Practices",
              "description": "Guidelines for implementing automated functional, performance, and security testing throughout the API lifecycle.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 133,
              "outcomes": [
                "Shared understanding of the purpose and use of API Testing Best Practices",
                "A consistent approach to applying API Testing Best Practices",
                "Improved application of the related practices"
              ],
              "steps": [
                "Test APIs for functionality, security, and performance using automated testing tools.",
                "Integrate functional and non-functional testing into the CI/CD pipeline to ensure APIs meet quality standards.",
                "Use automated testing tools to validate API functionality, security, and performance."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "apiops-CI-CD-for-apis",
              "slug": "resources/apiops-CI-CD-for-apis",
              "title": "APIOps CI/CD For APIs",
              "description": "Deployment guidance that integrates API lifecycle tasks—design, testing, governance—into continuous integration and delivery pipelines.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 140,
              "outcomes": [
                "Shared understanding of the purpose and use of APIOps CI/CD For APIs",
                "A consistent approach to applying APIOps CI/CD For APIs",
                "Improved application of the related practices"
              ],
              "steps": [
                "Use CI/CD pipelines to automate build, test, and deployment processes, ensuring consistent quality and traceability.",
                "Integrate automated tests into the CI/CD pipeline to ensure continuous validation of API quality.",
                "Implement deployment strategies (e.g., blue-green deployments, canary releases) to minimize risks during API releases.",
                "Establish a habit of reviewing metrics and planning continuous improvement activities."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "api-audit-checklist",
              "slug": "resources/api-audit-checklist",
              "title": "API Audit Checklist",
              "description": "A lifecycle-based checklist to verify API readiness across design, delivery, publishing, and compliance using defined audit criteria and evidence.",
              "category": "checklist",
              "icon": "check-box-outline",
              "order": 13,
              "outcomes": [
                "Shared understanding of the purpose and use of API Audit Checklist",
                "A consistent approach to applying API Audit Checklist",
                "Improved application of the related practices"
              ],
              "steps": [
                "Use the API Audit Checklist to ensure the API design meets functional and non-functional requirements, including security, performance, and compliance.",
                "Conduct audits to assess lifecycle coverage and verify that the API meets business, design, and operational standards.",
                "Ensure that documentation, security models, gateway configuration, and legal requirements are clearly defined, validated, and supported by evidence."
              ],
              "canvasId": null,
              "sourcePath": "src/snippets/api-audit-checklist.json",
              "sourceUrl": null,
              "contentMarkdown": "{\r\n  \"profiles\": {\r\n    \"read-only\": {\r\n      \"description\": \"API profile that is read-only and does not allow create, update, or delete operations.\"\r\n    },\r\n    \"full-crud\": {\r\n      \"description\": \"General API profile that allows create, update, and delete operations.\"\r\n    }\r\n  },\r\n  \"lifecycleStages\": [\r\n    {\r\n      \"id\": \"strategy\",\r\n      \"title\": \"Strategy\",\r\n      \"readinessLabel\": \"Strategy is Ready When...\",\r\n      \"order\": 1\r\n    },\r\n    {\r\n      \"id\": \"architecture\",\r\n      \"title\": \"Architecture\",\r\n      \"readinessLabel\": \"Architecture is Ready When...\",\r\n      \"order\": 2\r\n    },\r\n    {\r\n      \"id\": \"design\",\r\n      \"title\": \"Design\",\r\n      \"readinessLabel\": \"Design is Ready When...\",\r\n      \"order\": 3\r\n    },\r\n    {\r\n      \"id\": \"delivery\",\r\n      \"title\": \"Delivery\",\r\n      \"readinessLabel\": \"Delivery is Ready When...\",\r\n      \"order\": 4\r\n    },\r\n    {\r\n      \"id\": \"publishing\",\r\n      \"title\": \"Publishing\",\r\n      \"readinessLabel\": \"Publishing is Ready When...\",\r\n      \"order\": 5\r\n    },\r\n    {\r\n      \"id\": \"improving\",\r\n      \"title\": \"Improving\",\r\n      \"readinessLabel\": \"Improving is Ready When...\",\r\n      \"order\": 6\r\n    }\r\n  ],\r\n  \"stages\": [\r\n    {\r\n      \"id\": \"strategy\",\r\n      \"title\": \"Strategy\",\r\n      \"readinessLabel\": \"Strategy is Ready When...\",\r\n      \"order\": 1,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"based-on-clear-business-needs\",\r\n          \"label\": \"API is based on clear business needs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"strategy\",\r\n          \"producedByStation\": [\r\n            \"api-product-strategy\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"business-goals-defined\",\r\n            \"market-research-done\",\r\n            \"stakeholder-approval\",\r\n            \"metrics-feedback-available\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DOMAIN-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiBusinessModelCanvas\",\r\n            \"apiValuePropositionCanvas\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"design-artifact\",\r\n            \"documentation\",\r\n            \"research\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-product-strategy/apiValuePropositionCanvas.empty.json\",\r\n            \"specs/canvases/api-product-strategy/apiBusinessModelCanvas.empty.json\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"concept-items-audited\",\r\n          \"label\": \"All concept checklist items are audited\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"aggregate\",\r\n          \"check\": {\r\n            \"type\": \"stageCoverage\",\r\n            \"stageId\": \"strategy\"\r\n          },\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"strategy\",\r\n          \"producedByStation\": [\r\n            \"api-product-strategy\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"business-goals-defined\",\r\n            \"market-research-done\",\r\n            \"stakeholder-approval\",\r\n            \"metrics-feedback-available\",\r\n            \"api-opportunity-documented\",\r\n            \"api-reusability\",\r\n            \"value-prop-validated\",\r\n            \"consumer-segments-identified\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"report\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"audit/concept-review-report.json\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"architecture\",\r\n      \"title\": \"Architecture\",\r\n      \"readinessLabel\": \"Architecture is Ready When...\",\r\n      \"order\": 2,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"versioning-decided\",\r\n          \"label\": \"Versioning strategy decided and supported by gateway\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"architecture\",\r\n          \"producedByStation\": [\r\n            \"api-platform-architecture\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-roadmap-defined\",\r\n            \"api-reusability\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-VERSION-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"contract-first-design\",\r\n            \"api-versioning-best-practices\",\r\n            \"apiops-CI-CD-for-apis\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"ci-cd\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"docs/api/architecture/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"only-via-gateway\",\r\n          \"label\": \"Only accessible via API gateway\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"architecture\",\r\n          \"producedByStation\": [\r\n            \"api-platform-architecture\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-reusability\",\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-02\",\r\n            \"REST-CAPACITY-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"businessImpactCanvas\",\r\n            \"locationsCanvas\",\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"gateway-config\",\r\n            \"infra-config\",\r\n            \"security-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/architecture/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"rate-limits-enforced\",\r\n          \"label\": \"Rate limits are enforced\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"architecture\",\r\n          \"producedByStation\": [\r\n            \"api-platform-architecture\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-roadmap-defined\",\r\n            \"api-reusability\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CAPACITY-01\",\r\n            \"REST-OBS-01\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"capacityCanvas\",\r\n            \"api-security-best-practices\",\r\n            \"scalable-infrastructure-best-practices\",\r\n            \"api-metrics-and-analytics\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"gateway-config\",\r\n            \"runtime\",\r\n            \"monitoring\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-platform-architecture/capacityCanvas.empty.json\",\r\n            \"docs/api/architecture/README.md\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"design\",\r\n      \"title\": \"Design\",\r\n      \"readinessLabel\": \"Design is Ready When...\",\r\n      \"order\": 3,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"endpoint-descriptions-present\",\r\n          \"label\": \"Endpoints have business value and feature descriptions\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"operationDescriptions\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"value-prop-validated\",\r\n            \"api-opportunity-documented\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CX-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiValuePropositionCanvas\",\r\n            \"customerJourneyCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"design-artifact\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"specs/canvases/api-product-strategy/apiValuePropositionCanvas.empty.json\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"hides-raw-backend-data\",\r\n          \"label\": \"API hides raw backend data and is designed for shared use\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"hide-backend-discrepancies\",\r\n            \"design-reflects-business-value\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DOMAIN-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"interactionCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"design-artifact\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-product-strategy/domainCanvas.empty.json\",\r\n            \"specs/canvases/api-design/interactionCanvas.empty.json\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"design-consistent\",\r\n          \"label\": \"API design is consistent with other APIs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-platform-architecture\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"architecture-patterns-validated\",\r\n            \"api-reusability\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DOMAIN-02\",\r\n            \"REST-CX-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"documentation\",\r\n            \"design-artifact\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-design/restCanvas.empty.json\",\r\n            \"docs/api/design/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"descriptive-english-naming\",\r\n          \"label\": \"Data and attribute naming uses descriptive English\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"fieldNamesDescriptive\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-NAMING-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"mandatory-fields-specified\",\r\n          \"label\": \"Mandatory fields are specified\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"requiredFieldsPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-VALIDATION-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"contract\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"dates-use-iso\",\r\n          \"label\": \"Dates use ISO format with timezone\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"dateFormatTimezone\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DATA-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"general-data-uses-standard-values\",\r\n          \"label\": \"General data uses standard values\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"standardizedEnumsOrPatterns\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"design-reflects-business-value\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DATA-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"field-names-avoid-acronyms\",\r\n          \"label\": \"Field names avoid acronyms and use full words\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"avoidAcronyms\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-NAMING-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"create-returns-identifiers\",\r\n          \"label\": \"Creating new resources returns identifiers\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is read-only and does not create resources.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-201-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"paths-max-two-resources\",\r\n          \"label\": \"Endpoint paths contain max two resources or sub-resources\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"pathDepthMax\",\r\n            \"maxDepth\": 2\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PATH-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"examples-present\",\r\n          \"label\": \"Endpoints and attributes include examples\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"examplesPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CX-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"restCanvas\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"post-for-create-update\",\r\n          \"label\": \"POST is used for create or update\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose create or update operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"design-reflects-business-value\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-POST-01\",\r\n            \"REST-HTTP-PUT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"delete-for-remove\",\r\n          \"label\": \"DELETE is used to remove resources\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose delete operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-DELETE-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"get-no-request-body\",\r\n          \"label\": \"GET has no request body and returns content\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"getNoRequestBody\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-GET-01\",\r\n            \"REST-RESP-200-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"get-empty-returns-204\",\r\n          \"label\": \"GET returns 204 if response body is empty\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"The current contract returns content for all GET operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-204-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"post-returns-200\",\r\n          \"label\": \"POST returns 200 OK when updating\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose POST updates.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-200-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"post-returns-201\",\r\n          \"label\": \"POST returns 201 Created with ID on create\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose POST creates.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-201-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"delete-returns-204\",\r\n          \"label\": \"DELETE returns 204 on success\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose DELETE operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-204-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"400-errors-specific\",\r\n          \"label\": \"400 errors provide specific error information\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"errorResponsesSpecific\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-ERROR-400-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"restCanvas\",\r\n            \"api-audit-checklist\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"401-unauthorized\",\r\n          \"label\": \"401 Unauthorized for wrong credentials\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"The current public storefront contract is intentionally unauthenticated.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-ERROR-401-01\",\r\n            \"REST-SEC-01\",\r\n            \"REST-SEC-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"security-config\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"403-forbidden\",\r\n          \"label\": \"403 Forbidden for unauthorized operations\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"The current profile is public read-only and exposes no unauthorized operations.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-ERROR-403-01\",\r\n            \"REST-SEC-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"security-config\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"spec-contains-schemas\",\r\n          \"label\": \"Spec contains request and response schema\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"schemasPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CONTRACT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"contract-first-design\",\r\n            \"restCanvas\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"contract\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"pseudo-identifiers\",\r\n          \"label\": \"UUIDs or pseudo-identifiers instead of DB IDs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"opaqueIdentifiers\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"hide-backend-discrepancies\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-07\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"contract-first-design\",\r\n            \"api-security-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"no-sensitive-data-in-urls\",\r\n          \"label\": \"No sensitive data in URLs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"noSensitiveDataInPaths\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"hide-backend-discrepancies\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-06\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"contract-first-design\",\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"http-methods-match-resources\",\r\n          \"label\": \"HTTP methods only for intended resources\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"methodResourceConsistency\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-GET-01\",\r\n            \"REST-HTTP-POST-01\",\r\n            \"REST-HTTP-PUT-01\",\r\n            \"REST-HTTP-DELETE-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"delivery\",\r\n      \"title\": \"Delivery\",\r\n      \"readinessLabel\": \"Delivery is Ready When...\",\r\n      \"order\": 4,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"design-items-audited\",\r\n          \"label\": \"All prototype and design items are audited\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"aggregate\",\r\n          \"check\": {\r\n            \"type\": \"stageCoverage\",\r\n            \"stageId\": \"design\"\r\n          },\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"design-reflects-business-value\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"report\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"audit/production-readiness-review.json\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"spec-validated-on-change\",\r\n          \"label\": \"Spec validated on every change\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"validationWorkflowPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-audit-checklist\",\r\n            \"contract-first-design\",\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"api-testing-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"ci-cd\",\r\n            \"spec\",\r\n            \"test\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \".github/workflows/openapi-lint.yml\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"schema-and-examples-pass\",\r\n          \"label\": \"Schema and examples pass validation\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"examplesPassValidation\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"architecture-patterns-validated\",\r\n            \"api-contract-tested\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-01\",\r\n            \"REST-CONTRACT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"contract-first-design\",\r\n            \"api-audit-checklist\",\r\n            \"api-testing-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"test\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"uses-https\",\r\n          \"label\": \"Uses HTTPS or encrypted protocols\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-05\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"auth-protection\",\r\n          \"label\": \"Endpoints protected by authentication\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is intentionally public read-only.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-01\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"gateway-config\",\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"token-auth\",\r\n          \"label\": \"Token-based authentication\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is intentionally public read-only.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"csrf-protection\",\r\n          \"label\": \"Protected against CSRF\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is intentionally public read-only.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-08\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-development-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"code\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"inputs-auto-validated\",\r\n          \"label\": \"Inputs auto-validated by framework\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-VALIDATION-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-development-best-practices\",\r\n            \"contract-first-design\",\r\n            \"api-testing-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"code\",\r\n            \"test\",\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"docs/api/delivery/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"outputs-auto-escaped\",\r\n          \"label\": \"Outputs auto-escaped by framework\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"JSON APIs do not typically require output escaping in the same way as HTML rendering.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-development-best-practices\",\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"code\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"encryption-in-transit\",\r\n          \"label\": \"Encryption for data in transit and storage\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-05\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\",\r\n            \"api-metrics-and-analytics\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"infra-config\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"message-integrity\",\r\n          \"label\": \"Message integrity implemented\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-OBS-01\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"api-compliance-best-practices\",\r\n            \"api-metrics-and-analytics\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"monitoring\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/architecture/README.md\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"publishing\",\r\n      \"title\": \"Publishing\",\r\n      \"readinessLabel\": \"Publishing is Ready When...\",\r\n      \"order\": 5,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"published-via-api-management\",\r\n          \"label\": \"Published via API management\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"api-onboarding-best-practices\",\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"gateway-config\",\r\n            \"ci-cd\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \".github/workflows/openapi-lint.yml\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"visible-in-dev-portal\",\r\n          \"label\": \"Visible in developer portal\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-documentation-ready\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"api-community-engagement-strategies\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"documentation\",\r\n            \"runtime\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"docs-auto-generated\",\r\n          \"label\": \"Docs auto-generated from spec and schema\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\",\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-documentation-ready\",\r\n            \"api-ready-for-publishing\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CONTRACT-02\",\r\n            \"REST-PUBLISH-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"contract-first-design\",\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"api-onboarding-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"documentation\",\r\n            \"ci-cd\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"docs/api/audit/design-audit.read-only.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"spec-auto-updated\",\r\n          \"label\": \"Spec auto-updated to gateway and dev portal\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\",\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CONTRACT-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"contract-first-design\",\r\n            \"api-onboarding-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"ci-cd\",\r\n            \"gateway-config\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \".github/workflows/openapi-lint.yml\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"official-domain\",\r\n          \"label\": \"Published under official organization domain\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"documentation\",\r\n            \"runtime\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"improving\",\r\n      \"title\": \"Improving\",\r\n      \"readinessLabel\": \"Improving is Ready When...\",\r\n      \"order\": 6,\r\n      \"items\": []\r\n    }\r\n  ],\r\n  \"guidelines\": [\r\n    {\r\n      \"id\": \"REST-CONTRACT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST implement endpoints, parameters, request bodies, response bodies, and error responses as defined in the validated OpenAPI contract.\",\r\n      \"relatedAuditItems\": [\r\n        \"spec-contains-schemas\",\r\n        \"schema-and-examples-pass\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CONTRACT-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST keep the implementation, published OpenAPI description, gateway configuration, and developer portal documentation aligned on every change.\",\r\n      \"relatedAuditItems\": [\r\n        \"docs-auto-generated\",\r\n        \"spec-auto-updated\",\r\n        \"spec-validated-on-change\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-VALIDATION-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST validate path parameters, query parameters, headers, and JSON request bodies against the OpenAPI schema before business processing.\",\r\n      \"relatedAuditItems\": [\r\n        \"mandatory-fields-specified\",\r\n        \"400-errors-specific\",\r\n        \"inputs-auto-validated\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DOMAIN-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST expose business-oriented resources and attributes rather than raw backend tables, internal service payloads, or system-specific field names.\",\r\n      \"relatedAuditItems\": [\r\n        \"based-on-clear-business-needs\",\r\n        \"hides-raw-backend-data\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DOMAIN-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST preserve validated meanings of entities, attributes, statuses, and source-of-truth rules across all endpoints and operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"design-consistent\",\r\n        \"general-data-uses-standard-values\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-NAMING-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST use descriptive English names for resources and attributes.\",\r\n      \"relatedAuditItems\": [\r\n        \"descriptive-english-naming\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-NAMING-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST avoid unexplained acronyms in public field and resource names.\",\r\n      \"relatedAuditItems\": [\r\n        \"field-names-avoid-acronyms\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DATA-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST use ISO date-time values with timezone information where dates are exposed.\",\r\n      \"relatedAuditItems\": [\r\n        \"dates-use-iso\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DATA-02\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API SHOULD use standard codes, controlled vocabularies, and standardized value sets where applicable.\",\r\n      \"relatedAuditItems\": [\r\n        \"general-data-uses-standard-values\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API MUST describe the business value and feature intent of each endpoint or capability.\",\r\n      \"relatedAuditItems\": [\r\n        \"endpoint-descriptions-present\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API MUST include examples for endpoints, request bodies, response bodies, and key attributes.\",\r\n      \"relatedAuditItems\": [\r\n        \"examples-present\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-03\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API SHOULD use consistent pagination, filtering, sorting, and response conventions across resources.\",\r\n      \"relatedAuditItems\": [\r\n        \"design-consistent\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-GET-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use GET for safe read-only operations and MUST NOT define a request body for GET operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-no-request-body\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-POST-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use POST for resource creation and other non-idempotent operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"post-for-create-update\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-PUT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use PUT only for full resource replacement.\",\r\n      \"relatedAuditItems\": [\r\n        \"post-for-create-update\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-DELETE-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use DELETE to remove resources.\",\r\n      \"relatedAuditItems\": [\r\n        \"delete-for-remove\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PATH-01\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"resource-modeling\",\r\n      \"requirement\": \"The REST API SHOULD keep endpoint paths shallow and avoid more than two resource or sub-resource levels unless explicitly justified.\",\r\n      \"relatedAuditItems\": [\r\n        \"paths-max-two-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-200-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 200 OK for successful reads and updates that include a response body.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-no-request-body\",\r\n        \"post-returns-200\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-201-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 201 Created and the created resource identifier when a new resource is created.\",\r\n      \"relatedAuditItems\": [\r\n        \"create-returns-identifiers\",\r\n        \"post-returns-201\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-204-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 204 No Content for successful delete operations that do not return a body.\",\r\n      \"relatedAuditItems\": [\r\n        \"delete-returns-204\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-204-02\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API SHOULD return 204 No Content for successful operations that intentionally return no response body.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-empty-returns-204\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-400-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST define 400 Bad Request responses with specific and actionable validation error information.\",\r\n      \"relatedAuditItems\": [\r\n        \"400-errors-specific\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-401-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST return 401 Unauthorized for missing or invalid credentials.\",\r\n      \"relatedAuditItems\": [\r\n        \"401-unauthorized\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-403-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST return 403 Forbidden for authenticated clients lacking sufficient permission.\",\r\n      \"relatedAuditItems\": [\r\n        \"403-forbidden\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-VERSION-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"versioning\",\r\n      \"requirement\": \"The REST API MUST define a versioning strategy before production release, and the strategy MUST be supportable by the API gateway.\",\r\n      \"relatedAuditItems\": [\r\n        \"versioning-decided\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST require authentication for protected endpoints.\",\r\n      \"relatedAuditItems\": [\r\n        \"auth-protection\",\r\n        \"401-unauthorized\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST use token-based authentication or another approved modern authentication mechanism for protected endpoints.\",\r\n      \"relatedAuditItems\": [\r\n        \"token-auth\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-03\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST enforce object-level and function-level authorization on every protected operation.\",\r\n      \"relatedAuditItems\": [\r\n        \"401-unauthorized\",\r\n        \"403-forbidden\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-04\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST mitigate OWASP API risks including broken object level authorization, broken function level authorization, injection, and unrestricted resource consumption.\",\r\n      \"relatedAuditItems\": [\r\n        \"auth-protection\",\r\n        \"rate-limits-enforced\",\r\n        \"no-sensitive-data-in-urls\",\r\n        \"message-integrity\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-05\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST use HTTPS or another approved encrypted protocol for all traffic.\",\r\n      \"relatedAuditItems\": [\r\n        \"uses-https\",\r\n        \"encryption-in-transit\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-06\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST NOT expose sensitive information in URLs, query strings, logs, or unnecessary response fields.\",\r\n      \"relatedAuditItems\": [\r\n        \"no-sensitive-data-in-urls\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-07\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API SHOULD use UUIDs or other non-sequential public identifiers where direct database identifiers would increase exposure risk.\",\r\n      \"relatedAuditItems\": [\r\n        \"pseudo-identifiers\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-08\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST implement CSRF protection where relevant to the authentication model and client interaction pattern.\",\r\n      \"relatedAuditItems\": [\r\n        \"csrf-protection\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CAPACITY-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"resilience-capacity\",\r\n      \"requirement\": \"The REST API MUST define and enforce rate limits, throttling, or quotas according to capacity expectations.\",\r\n      \"relatedAuditItems\": [\r\n        \"rate-limits-enforced\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CAPACITY-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"resilience-capacity\",\r\n      \"requirement\": \"The REST API MUST implement resilience controls such as timeouts, fallback behavior, and degradation handling according to business impact.\",\r\n      \"relatedAuditItems\": [\r\n        \"only-via-gateway\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-OBS-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"observability\",\r\n      \"requirement\": \"The REST API MUST implement logs, metrics, and monitoring needed to observe validation failures, auth failures, traffic, latency, and dependency health.\",\r\n      \"relatedAuditItems\": [\r\n        \"rate-limits-enforced\",\r\n        \"message-integrity\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be published through an API management platform.\",\r\n      \"relatedAuditItems\": [\r\n        \"published-via-api-management\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be accessible only through approved API gateway paths and managed entry points.\",\r\n      \"relatedAuditItems\": [\r\n        \"only-via-gateway\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-03\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API SHOULD be visible in a developer portal with documentation generated from the contract.\",\r\n      \"relatedAuditItems\": [\r\n        \"visible-in-dev-portal\",\r\n        \"docs-auto-generated\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-04\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be published under an approved organizational domain.\",\r\n      \"relatedAuditItems\": [\r\n        \"official-domain\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-AUDIT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST validate the specification, schema, and examples on every change.\",\r\n      \"relatedAuditItems\": [\r\n        \"spec-validated-on-change\",\r\n        \"schema-and-examples-pass\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-AUDIT-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST pass concept, design, security, and production-readiness checks before release.\",\r\n      \"relatedAuditItems\": [\r\n        \"concept-items-audited\",\r\n        \"design-items-audited\"\r\n      ]\r\n    }\r\n  ]\r\n}\r\n",
              "draft": false
            }
          ],
          "promptIds": [
            "security-specialist:facilitate-station",
            "security-specialist:use-resources",
            "security-specialist:next-actions"
          ]
        },
        {
          "id": "operations-specialist",
          "stakeholderId": "operations-specialist",
          "title": "Support and Operations Owner",
          "summary": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
          "stakeholder": {
            "id": "operations-specialist",
            "sourceKey": "operations-specialist",
            "sourceStakeholderId": "operations-specialist",
            "title": "Support and Operations Owner",
            "description": "Represents runtime support, incident handling, observability, and operational readiness for the capability, API, or automation.",
            "involvement": ""
          },
          "cycles": [
            {
              "id": "capability-productization-cycle",
              "title": "Capability Productization Cycle",
              "description": "A cycle for turning business capabilities into reusable digital capabilities before selecting the implementation style."
            },
            {
              "id": "api-productization-cycle",
              "title": "API Productization Cycle",
              "description": "The API-focused APIOps Cycles journey for productizing, designing, delivering, publishing, and improving APIs."
            },
            {
              "id": "integration-productization-cycle",
              "title": "Integration Productization Cycle",
              "description": "A cycle for productizing reusable integration capabilities before selecting the implementation style."
            },
            {
              "id": "automation-cycle",
              "title": "Automation Cycle",
              "description": "A cycle for identifying, designing, delivering, enabling, and improving automation opportunities."
            }
          ],
          "stations": [
            {
              "id": "api-consumer-experience",
              "title": "Consumer Requirements & Onboarding",
              "description": "Capture consumer onboarding, standards, non-functional requirements, service expectations, constraints, security needs, allowed protocols, data freshness, SLAs, observability, recovery, adoption requirements, and producer responsibilities."
            },
            {
              "id": "api-delivery",
              "title": "Delivery & Operations",
              "description": "Deliver the selected implementation style with appropriate engineering, testing, security, automation, and operational practices."
            },
            {
              "id": "api-audit",
              "title": "Quality & Readiness Assurance",
              "description": "Audit the capability interface contract, controls, support model, observability, documentation, and lifecycle readiness before release."
            },
            {
              "id": "api-publishing",
              "title": "Publishing & Enablement",
              "description": "Publish reusable capability information so consumers can discover, request, onboard, use, and get support."
            },
            {
              "id": "monitoring-and-improving",
              "title": "Monitoring & Improvement",
              "description": "Monitor usage, reliability, data quality, consumer outcomes, operational cost, and reuse opportunities after release."
            },
            {
              "id": "api-platform-architecture",
              "title": "Architecture & Platform Decisions",
              "description": "Use requirements and constraints to decide the right architecture pattern and enabling platform capabilities."
            }
          ],
          "canvases": [
            {
              "id": "consumerExperienceRequirementsCanvas",
              "title": "Consumer Experience Requirements Canvas"
            },
            {
              "id": "businessImpactCanvas",
              "title": "Business Impact Canvas"
            },
            {
              "id": "locationsCanvas",
              "title": "Locations Canvas"
            },
            {
              "id": "capacityCanvas",
              "title": "Capacity Canvas"
            },
            {
              "id": "apiValuePropositionCanvas",
              "title": "API Value Proposition Canvas"
            },
            {
              "id": "customerJourneyCanvas",
              "title": "Customer Journey Canvas"
            }
          ],
          "decisions": [
            "Use the Consumer Experience Requirements Canvas to capture consumer goals, availability, freshness, volume, performance, data quality, security, onboarding, change, observability, and recovery expectations.",
            "Use onboarding guidance to describe how consumers will find, request, test, get approved for, and start using the capability.",
            "Use the resulting journey and requirements to improve onboarding, documentation, support, and feedback loops for capability consumers.",
            "Use consumer experience and onboarding guidance to make expectations explicit for both consumers and producers.",
            "The right architecture depends on consumer goals, onboarding expectations, service levels, data quality needs, change tolerance, observability, support, and producer constraints.",
            "Use development best practices to implement the validated interface contract with established frameworks, libraries, and team standards."
          ],
          "outputs": [
            "Documented consumer requirements and onboarding expectations",
            "Clear producer responsibilities and support expectations",
            "Architecture-relevant constraints ready for decision making",
            "Improved adoption through consumer empathy, standards, and producer clarity",
            "design-artifact",
            "documentation",
            "consumer-feedback",
            "A delivered capability aligned with the validated interface contract"
          ],
          "recommendedResources": [
            {
              "id": "consumerExperienceRequirementsCanvas",
              "slug": "resources/consumer-experience-requirements-canvas",
              "title": "Consumer Experience Requirements Canvas",
              "description": "A requirements canvas for consumer experience and non-functional needs that should guide the later architecture and implementation-style decision.",
              "category": "canvas",
              "icon": "dashboard-outline",
              "order": 3.2,
              "outcomes": [
                "Technology-agnostic consumer and service requirements",
                "Experience and non-functional needs captured before design starts",
                "Architecture implications documented for implementation-style selection"
              ],
              "steps": [
                "Capture consumer goals and usage context.",
                "Document availability, timeliness, volume, performance, data quality, and consistency expectations.",
                "Document security, privacy, onboarding, change, observability, support, and recovery expectations.",
                "Summarize what the requirements imply for possible implementation styles."
              ],
              "canvasId": "consumerExperienceRequirementsCanvas",
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": false
            },
            {
              "id": "api-onboarding-best-practices",
              "slug": "resources/api-onboarding-best-practices",
              "title": "API Onboarding Best Practices",
              "description": "Best practices to streamline API consumer onboarding journeys with step-by-step registration, discovery, and first-call guidance.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 121,
              "outcomes": [
                "Shared understanding of the purpose and use of API Onboarding Best Practices",
                "A consistent approach to applying API Onboarding Best Practices",
                "Improved application of the related practices"
              ],
              "steps": [
                "Define the API consumer journey from discovery to troubleshooting, identifying key touchpoints and pain points.",
                "Develop onboarding processes and resources to help API consumers understand how to use APIs effectively.",
                "Document how consumers find and use the API, including onboarding processes and registration."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "api-development-best-practices",
              "slug": "resources/api-development-best-practices",
              "title": "API Development Best Practices",
              "description": "Implementation guidance for turning a validated API interface contract into a consistent, maintainable API codebase using standard libraries, reusable patterns, and aligned development workflows.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 112,
              "outcomes": [
                "Shared understanding of the purpose and use of API Development Best Practices",
                "A consistent approach to applying API Development Best Practices",
                "Improved application of the related practices"
              ],
              "steps": [
                "Apply these practices to the validated API interface contract and implementation plan before coding begins.",
                "Use established frameworks, libraries, and coding standards to implement the contract consistently and maintainably."
              ],
              "canvasId": null,
              "sourcePath": "src/snippets/api-design-principles-guidance.md",
              "sourceUrl": null,
              "contentMarkdown": "## How to start the API Delivery work based on the previous phases (\"stations\")\r\n\r\nUse this guidance at the start of `API Delivery` after the API contract (e.g. OpenAPI) and the key outputs from earlier stations have been reviewed and accepted.\r\n\r\nThe goal is not to invent implementation in isolation. The goal is to turn the agreed outputs from earlier stations into concrete code structure, validation rules, runtime behavior, and API product delivery decisions.\r\n\r\n---\r\n\r\n### 1. Start From The Validated Contract\r\n\r\n- Treat the validated API contract as the main reference point for implementation decisions.\r\n- Keep the contract and implementation aligned throughout the API product delivery.\r\n- Use the contract to drive request validation, response mapping, documentation, and tests.\r\n\r\n---\r\n\r\n### 2. Use Domain Outputs To Preserve Business Meaning\r\n\r\n- Use the `Domain Canvas` outputs to guide naming, how the implementation is split into clear business responsibilities, and how different backend systems are connected without exposing their differences.\r\n- Preserve the validated meanings of entities, attributes, statuses, and source-of-truth rules.\r\n- Avoid leaking backend-specific models or inconsistencies into the public API.\r\n\r\n---\r\n\r\n### 3. Use Journey Outputs To Preserve Critical Flows\r\n\r\n- Use the `Customer Journey Canvas` outputs to identify which user flows are most important to support first.\r\n- Use the `API Consumer Experience` outputs to keep the API understandable, predictable, and easy to integrate.\r\n- Let the agreed journey priorities decide which implementation paths need the highest reliability, lowest latency, clearest errors, and strongest operational focus.\r\n\r\n---\r\n\r\n### 4. Use Value Proposition Outputs To Preserve Consumer Value\r\n\r\n- Use the `API Value Proposition Canvas` outputs to keep the implementation focused on the agreed pains, gains, and API features.\r\n- Preserve the field meanings, behavior, and promises that made the API valuable in the earlier stations.\r\n- Ensure error handling, freshness, and naming support both the intended developer experience and the business use case.\r\n\r\n---\r\n\r\n### 5. Use Architecture Outputs To Shape Runtime Decisions\r\n\r\n- Use the `Business Impact Canvas` outputs to guide resilience, timeout, fallback, and degradation decisions.\r\n- Use the `Locations Canvas` outputs to guide network boundaries, trust boundaries, access paths, and deployment constraints.\r\n- Use the `Capacity Canvas` outputs to guide rate limits, caching, scaling, and peak-load behavior.\r\n- Use the `API Metrics And Analytics` guidance to decide what must be observed from the first implementation onward.\r\n\r\n---\r\n\r\n### 6. Use Interaction And Protocol Design Outputs To Shape Code Structure\r\n\r\n- Use the `Interaction Canvas` outputs to avoid implementing unsupported interaction styles too early.\r\n- Use the `REST`, `Event`, or `GraphQL` design outputs to shape protocol-specific request, response, and validation behavior.\r\n- Reflect the selected interaction style clearly in code structure, responsibilities, and testing strategy.\r\n\r\n---\r\n\r\n### 7. Use Audit Outputs To Improve Delivery Before Coding Goes Too Far\r\n\r\n- Use the audit findings to remove ambiguity before implementation spreads across the codebase.\r\n- Fix unclear request rules, missing validation, weak error contracts, and operational gaps early.\r\n- Treat audit as a design-improvement loop before production, not only as a final decision gate.\r\n\r\n---\r\n\r\n### 8. Apply The Guidance, Then Summarize\r\n\r\n- Apply this guidance to the current API and implementation plan.\r\n- Summarize the implications for code structure, request validation, source integration, security, monitoring and alerts, and testing.\r\n- Do not create a separate delivery artifact unless the team or user specifically needs one.\r\n",
              "draft": true
            },
            {
              "id": "api-testing-best-practices",
              "slug": "resources/api-testing-best-practices",
              "title": "API Testing Best Practices",
              "description": "Guidelines for implementing automated functional, performance, and security testing throughout the API lifecycle.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 133,
              "outcomes": [
                "Shared understanding of the purpose and use of API Testing Best Practices",
                "A consistent approach to applying API Testing Best Practices",
                "Improved application of the related practices"
              ],
              "steps": [
                "Test APIs for functionality, security, and performance using automated testing tools.",
                "Integrate functional and non-functional testing into the CI/CD pipeline to ensure APIs meet quality standards.",
                "Use automated testing tools to validate API functionality, security, and performance."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "apiops-CI-CD-for-apis",
              "slug": "resources/apiops-CI-CD-for-apis",
              "title": "APIOps CI/CD For APIs",
              "description": "Deployment guidance that integrates API lifecycle tasks—design, testing, governance—into continuous integration and delivery pipelines.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 140,
              "outcomes": [
                "Shared understanding of the purpose and use of APIOps CI/CD For APIs",
                "A consistent approach to applying APIOps CI/CD For APIs",
                "Improved application of the related practices"
              ],
              "steps": [
                "Use CI/CD pipelines to automate build, test, and deployment processes, ensuring consistent quality and traceability.",
                "Integrate automated tests into the CI/CD pipeline to ensure continuous validation of API quality.",
                "Implement deployment strategies (e.g., blue-green deployments, canary releases) to minimize risks during API releases.",
                "Establish a habit of reviewing metrics and planning continuous improvement activities."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "api-audit-checklist",
              "slug": "resources/api-audit-checklist",
              "title": "API Audit Checklist",
              "description": "A lifecycle-based checklist to verify API readiness across design, delivery, publishing, and compliance using defined audit criteria and evidence.",
              "category": "checklist",
              "icon": "check-box-outline",
              "order": 13,
              "outcomes": [
                "Shared understanding of the purpose and use of API Audit Checklist",
                "A consistent approach to applying API Audit Checklist",
                "Improved application of the related practices"
              ],
              "steps": [
                "Use the API Audit Checklist to ensure the API design meets functional and non-functional requirements, including security, performance, and compliance.",
                "Conduct audits to assess lifecycle coverage and verify that the API meets business, design, and operational standards.",
                "Ensure that documentation, security models, gateway configuration, and legal requirements are clearly defined, validated, and supported by evidence."
              ],
              "canvasId": null,
              "sourcePath": "src/snippets/api-audit-checklist.json",
              "sourceUrl": null,
              "contentMarkdown": "{\r\n  \"profiles\": {\r\n    \"read-only\": {\r\n      \"description\": \"API profile that is read-only and does not allow create, update, or delete operations.\"\r\n    },\r\n    \"full-crud\": {\r\n      \"description\": \"General API profile that allows create, update, and delete operations.\"\r\n    }\r\n  },\r\n  \"lifecycleStages\": [\r\n    {\r\n      \"id\": \"strategy\",\r\n      \"title\": \"Strategy\",\r\n      \"readinessLabel\": \"Strategy is Ready When...\",\r\n      \"order\": 1\r\n    },\r\n    {\r\n      \"id\": \"architecture\",\r\n      \"title\": \"Architecture\",\r\n      \"readinessLabel\": \"Architecture is Ready When...\",\r\n      \"order\": 2\r\n    },\r\n    {\r\n      \"id\": \"design\",\r\n      \"title\": \"Design\",\r\n      \"readinessLabel\": \"Design is Ready When...\",\r\n      \"order\": 3\r\n    },\r\n    {\r\n      \"id\": \"delivery\",\r\n      \"title\": \"Delivery\",\r\n      \"readinessLabel\": \"Delivery is Ready When...\",\r\n      \"order\": 4\r\n    },\r\n    {\r\n      \"id\": \"publishing\",\r\n      \"title\": \"Publishing\",\r\n      \"readinessLabel\": \"Publishing is Ready When...\",\r\n      \"order\": 5\r\n    },\r\n    {\r\n      \"id\": \"improving\",\r\n      \"title\": \"Improving\",\r\n      \"readinessLabel\": \"Improving is Ready When...\",\r\n      \"order\": 6\r\n    }\r\n  ],\r\n  \"stages\": [\r\n    {\r\n      \"id\": \"strategy\",\r\n      \"title\": \"Strategy\",\r\n      \"readinessLabel\": \"Strategy is Ready When...\",\r\n      \"order\": 1,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"based-on-clear-business-needs\",\r\n          \"label\": \"API is based on clear business needs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"strategy\",\r\n          \"producedByStation\": [\r\n            \"api-product-strategy\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"business-goals-defined\",\r\n            \"market-research-done\",\r\n            \"stakeholder-approval\",\r\n            \"metrics-feedback-available\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DOMAIN-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiBusinessModelCanvas\",\r\n            \"apiValuePropositionCanvas\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"design-artifact\",\r\n            \"documentation\",\r\n            \"research\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-product-strategy/apiValuePropositionCanvas.empty.json\",\r\n            \"specs/canvases/api-product-strategy/apiBusinessModelCanvas.empty.json\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"concept-items-audited\",\r\n          \"label\": \"All concept checklist items are audited\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"aggregate\",\r\n          \"check\": {\r\n            \"type\": \"stageCoverage\",\r\n            \"stageId\": \"strategy\"\r\n          },\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"strategy\",\r\n          \"producedByStation\": [\r\n            \"api-product-strategy\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"business-goals-defined\",\r\n            \"market-research-done\",\r\n            \"stakeholder-approval\",\r\n            \"metrics-feedback-available\",\r\n            \"api-opportunity-documented\",\r\n            \"api-reusability\",\r\n            \"value-prop-validated\",\r\n            \"consumer-segments-identified\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"report\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"audit/concept-review-report.json\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"architecture\",\r\n      \"title\": \"Architecture\",\r\n      \"readinessLabel\": \"Architecture is Ready When...\",\r\n      \"order\": 2,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"versioning-decided\",\r\n          \"label\": \"Versioning strategy decided and supported by gateway\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"architecture\",\r\n          \"producedByStation\": [\r\n            \"api-platform-architecture\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-roadmap-defined\",\r\n            \"api-reusability\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-VERSION-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"contract-first-design\",\r\n            \"api-versioning-best-practices\",\r\n            \"apiops-CI-CD-for-apis\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"ci-cd\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"docs/api/architecture/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"only-via-gateway\",\r\n          \"label\": \"Only accessible via API gateway\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"architecture\",\r\n          \"producedByStation\": [\r\n            \"api-platform-architecture\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-reusability\",\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-02\",\r\n            \"REST-CAPACITY-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"businessImpactCanvas\",\r\n            \"locationsCanvas\",\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"gateway-config\",\r\n            \"infra-config\",\r\n            \"security-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/architecture/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"rate-limits-enforced\",\r\n          \"label\": \"Rate limits are enforced\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"architecture\",\r\n          \"producedByStation\": [\r\n            \"api-platform-architecture\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-roadmap-defined\",\r\n            \"api-reusability\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CAPACITY-01\",\r\n            \"REST-OBS-01\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"capacityCanvas\",\r\n            \"api-security-best-practices\",\r\n            \"scalable-infrastructure-best-practices\",\r\n            \"api-metrics-and-analytics\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"gateway-config\",\r\n            \"runtime\",\r\n            \"monitoring\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-platform-architecture/capacityCanvas.empty.json\",\r\n            \"docs/api/architecture/README.md\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"design\",\r\n      \"title\": \"Design\",\r\n      \"readinessLabel\": \"Design is Ready When...\",\r\n      \"order\": 3,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"endpoint-descriptions-present\",\r\n          \"label\": \"Endpoints have business value and feature descriptions\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"operationDescriptions\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"value-prop-validated\",\r\n            \"api-opportunity-documented\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CX-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiValuePropositionCanvas\",\r\n            \"customerJourneyCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"design-artifact\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"specs/canvases/api-product-strategy/apiValuePropositionCanvas.empty.json\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"hides-raw-backend-data\",\r\n          \"label\": \"API hides raw backend data and is designed for shared use\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"hide-backend-discrepancies\",\r\n            \"design-reflects-business-value\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DOMAIN-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"interactionCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"design-artifact\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-product-strategy/domainCanvas.empty.json\",\r\n            \"specs/canvases/api-design/interactionCanvas.empty.json\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"design-consistent\",\r\n          \"label\": \"API design is consistent with other APIs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-platform-architecture\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"architecture-patterns-validated\",\r\n            \"api-reusability\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DOMAIN-02\",\r\n            \"REST-CX-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"documentation\",\r\n            \"design-artifact\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-design/restCanvas.empty.json\",\r\n            \"docs/api/design/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"descriptive-english-naming\",\r\n          \"label\": \"Data and attribute naming uses descriptive English\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"fieldNamesDescriptive\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-NAMING-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"mandatory-fields-specified\",\r\n          \"label\": \"Mandatory fields are specified\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"requiredFieldsPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-VALIDATION-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"contract\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"dates-use-iso\",\r\n          \"label\": \"Dates use ISO format with timezone\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"dateFormatTimezone\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DATA-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"general-data-uses-standard-values\",\r\n          \"label\": \"General data uses standard values\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"standardizedEnumsOrPatterns\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"design-reflects-business-value\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DATA-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"field-names-avoid-acronyms\",\r\n          \"label\": \"Field names avoid acronyms and use full words\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"avoidAcronyms\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-NAMING-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"create-returns-identifiers\",\r\n          \"label\": \"Creating new resources returns identifiers\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is read-only and does not create resources.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-201-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"paths-max-two-resources\",\r\n          \"label\": \"Endpoint paths contain max two resources or sub-resources\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"pathDepthMax\",\r\n            \"maxDepth\": 2\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PATH-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"examples-present\",\r\n          \"label\": \"Endpoints and attributes include examples\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"examplesPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CX-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"restCanvas\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"post-for-create-update\",\r\n          \"label\": \"POST is used for create or update\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose create or update operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"design-reflects-business-value\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-POST-01\",\r\n            \"REST-HTTP-PUT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"delete-for-remove\",\r\n          \"label\": \"DELETE is used to remove resources\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose delete operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-DELETE-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"get-no-request-body\",\r\n          \"label\": \"GET has no request body and returns content\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"getNoRequestBody\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-GET-01\",\r\n            \"REST-RESP-200-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"get-empty-returns-204\",\r\n          \"label\": \"GET returns 204 if response body is empty\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"The current contract returns content for all GET operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-204-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"post-returns-200\",\r\n          \"label\": \"POST returns 200 OK when updating\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose POST updates.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-200-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"post-returns-201\",\r\n          \"label\": \"POST returns 201 Created with ID on create\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose POST creates.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-201-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"delete-returns-204\",\r\n          \"label\": \"DELETE returns 204 on success\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose DELETE operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-204-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"400-errors-specific\",\r\n          \"label\": \"400 errors provide specific error information\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"errorResponsesSpecific\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-ERROR-400-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"restCanvas\",\r\n            \"api-audit-checklist\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"401-unauthorized\",\r\n          \"label\": \"401 Unauthorized for wrong credentials\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"The current public storefront contract is intentionally unauthenticated.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-ERROR-401-01\",\r\n            \"REST-SEC-01\",\r\n            \"REST-SEC-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"security-config\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"403-forbidden\",\r\n          \"label\": \"403 Forbidden for unauthorized operations\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"The current profile is public read-only and exposes no unauthorized operations.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-ERROR-403-01\",\r\n            \"REST-SEC-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"security-config\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"spec-contains-schemas\",\r\n          \"label\": \"Spec contains request and response schema\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"schemasPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CONTRACT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"contract-first-design\",\r\n            \"restCanvas\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"contract\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"pseudo-identifiers\",\r\n          \"label\": \"UUIDs or pseudo-identifiers instead of DB IDs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"opaqueIdentifiers\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"hide-backend-discrepancies\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-07\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"contract-first-design\",\r\n            \"api-security-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"no-sensitive-data-in-urls\",\r\n          \"label\": \"No sensitive data in URLs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"noSensitiveDataInPaths\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"hide-backend-discrepancies\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-06\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"contract-first-design\",\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"http-methods-match-resources\",\r\n          \"label\": \"HTTP methods only for intended resources\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"methodResourceConsistency\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-GET-01\",\r\n            \"REST-HTTP-POST-01\",\r\n            \"REST-HTTP-PUT-01\",\r\n            \"REST-HTTP-DELETE-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"delivery\",\r\n      \"title\": \"Delivery\",\r\n      \"readinessLabel\": \"Delivery is Ready When...\",\r\n      \"order\": 4,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"design-items-audited\",\r\n          \"label\": \"All prototype and design items are audited\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"aggregate\",\r\n          \"check\": {\r\n            \"type\": \"stageCoverage\",\r\n            \"stageId\": \"design\"\r\n          },\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"design-reflects-business-value\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"report\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"audit/production-readiness-review.json\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"spec-validated-on-change\",\r\n          \"label\": \"Spec validated on every change\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"validationWorkflowPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-audit-checklist\",\r\n            \"contract-first-design\",\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"api-testing-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"ci-cd\",\r\n            \"spec\",\r\n            \"test\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \".github/workflows/openapi-lint.yml\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"schema-and-examples-pass\",\r\n          \"label\": \"Schema and examples pass validation\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"examplesPassValidation\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"architecture-patterns-validated\",\r\n            \"api-contract-tested\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-01\",\r\n            \"REST-CONTRACT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"contract-first-design\",\r\n            \"api-audit-checklist\",\r\n            \"api-testing-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"test\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"uses-https\",\r\n          \"label\": \"Uses HTTPS or encrypted protocols\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-05\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"auth-protection\",\r\n          \"label\": \"Endpoints protected by authentication\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is intentionally public read-only.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-01\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"gateway-config\",\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"token-auth\",\r\n          \"label\": \"Token-based authentication\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is intentionally public read-only.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"csrf-protection\",\r\n          \"label\": \"Protected against CSRF\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is intentionally public read-only.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-08\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-development-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"code\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"inputs-auto-validated\",\r\n          \"label\": \"Inputs auto-validated by framework\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-VALIDATION-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-development-best-practices\",\r\n            \"contract-first-design\",\r\n            \"api-testing-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"code\",\r\n            \"test\",\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"docs/api/delivery/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"outputs-auto-escaped\",\r\n          \"label\": \"Outputs auto-escaped by framework\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"JSON APIs do not typically require output escaping in the same way as HTML rendering.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-development-best-practices\",\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"code\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"encryption-in-transit\",\r\n          \"label\": \"Encryption for data in transit and storage\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-05\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\",\r\n            \"api-metrics-and-analytics\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"infra-config\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"message-integrity\",\r\n          \"label\": \"Message integrity implemented\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-OBS-01\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"api-compliance-best-practices\",\r\n            \"api-metrics-and-analytics\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"monitoring\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/architecture/README.md\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"publishing\",\r\n      \"title\": \"Publishing\",\r\n      \"readinessLabel\": \"Publishing is Ready When...\",\r\n      \"order\": 5,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"published-via-api-management\",\r\n          \"label\": \"Published via API management\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"api-onboarding-best-practices\",\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"gateway-config\",\r\n            \"ci-cd\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \".github/workflows/openapi-lint.yml\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"visible-in-dev-portal\",\r\n          \"label\": \"Visible in developer portal\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-documentation-ready\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"api-community-engagement-strategies\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"documentation\",\r\n            \"runtime\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"docs-auto-generated\",\r\n          \"label\": \"Docs auto-generated from spec and schema\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\",\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-documentation-ready\",\r\n            \"api-ready-for-publishing\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CONTRACT-02\",\r\n            \"REST-PUBLISH-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"contract-first-design\",\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"api-onboarding-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"documentation\",\r\n            \"ci-cd\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"docs/api/audit/design-audit.read-only.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"spec-auto-updated\",\r\n          \"label\": \"Spec auto-updated to gateway and dev portal\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\",\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CONTRACT-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"contract-first-design\",\r\n            \"api-onboarding-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"ci-cd\",\r\n            \"gateway-config\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \".github/workflows/openapi-lint.yml\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"official-domain\",\r\n          \"label\": \"Published under official organization domain\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"documentation\",\r\n            \"runtime\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"improving\",\r\n      \"title\": \"Improving\",\r\n      \"readinessLabel\": \"Improving is Ready When...\",\r\n      \"order\": 6,\r\n      \"items\": []\r\n    }\r\n  ],\r\n  \"guidelines\": [\r\n    {\r\n      \"id\": \"REST-CONTRACT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST implement endpoints, parameters, request bodies, response bodies, and error responses as defined in the validated OpenAPI contract.\",\r\n      \"relatedAuditItems\": [\r\n        \"spec-contains-schemas\",\r\n        \"schema-and-examples-pass\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CONTRACT-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST keep the implementation, published OpenAPI description, gateway configuration, and developer portal documentation aligned on every change.\",\r\n      \"relatedAuditItems\": [\r\n        \"docs-auto-generated\",\r\n        \"spec-auto-updated\",\r\n        \"spec-validated-on-change\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-VALIDATION-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST validate path parameters, query parameters, headers, and JSON request bodies against the OpenAPI schema before business processing.\",\r\n      \"relatedAuditItems\": [\r\n        \"mandatory-fields-specified\",\r\n        \"400-errors-specific\",\r\n        \"inputs-auto-validated\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DOMAIN-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST expose business-oriented resources and attributes rather than raw backend tables, internal service payloads, or system-specific field names.\",\r\n      \"relatedAuditItems\": [\r\n        \"based-on-clear-business-needs\",\r\n        \"hides-raw-backend-data\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DOMAIN-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST preserve validated meanings of entities, attributes, statuses, and source-of-truth rules across all endpoints and operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"design-consistent\",\r\n        \"general-data-uses-standard-values\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-NAMING-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST use descriptive English names for resources and attributes.\",\r\n      \"relatedAuditItems\": [\r\n        \"descriptive-english-naming\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-NAMING-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST avoid unexplained acronyms in public field and resource names.\",\r\n      \"relatedAuditItems\": [\r\n        \"field-names-avoid-acronyms\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DATA-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST use ISO date-time values with timezone information where dates are exposed.\",\r\n      \"relatedAuditItems\": [\r\n        \"dates-use-iso\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DATA-02\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API SHOULD use standard codes, controlled vocabularies, and standardized value sets where applicable.\",\r\n      \"relatedAuditItems\": [\r\n        \"general-data-uses-standard-values\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API MUST describe the business value and feature intent of each endpoint or capability.\",\r\n      \"relatedAuditItems\": [\r\n        \"endpoint-descriptions-present\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API MUST include examples for endpoints, request bodies, response bodies, and key attributes.\",\r\n      \"relatedAuditItems\": [\r\n        \"examples-present\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-03\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API SHOULD use consistent pagination, filtering, sorting, and response conventions across resources.\",\r\n      \"relatedAuditItems\": [\r\n        \"design-consistent\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-GET-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use GET for safe read-only operations and MUST NOT define a request body for GET operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-no-request-body\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-POST-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use POST for resource creation and other non-idempotent operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"post-for-create-update\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-PUT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use PUT only for full resource replacement.\",\r\n      \"relatedAuditItems\": [\r\n        \"post-for-create-update\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-DELETE-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use DELETE to remove resources.\",\r\n      \"relatedAuditItems\": [\r\n        \"delete-for-remove\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PATH-01\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"resource-modeling\",\r\n      \"requirement\": \"The REST API SHOULD keep endpoint paths shallow and avoid more than two resource or sub-resource levels unless explicitly justified.\",\r\n      \"relatedAuditItems\": [\r\n        \"paths-max-two-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-200-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 200 OK for successful reads and updates that include a response body.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-no-request-body\",\r\n        \"post-returns-200\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-201-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 201 Created and the created resource identifier when a new resource is created.\",\r\n      \"relatedAuditItems\": [\r\n        \"create-returns-identifiers\",\r\n        \"post-returns-201\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-204-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 204 No Content for successful delete operations that do not return a body.\",\r\n      \"relatedAuditItems\": [\r\n        \"delete-returns-204\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-204-02\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API SHOULD return 204 No Content for successful operations that intentionally return no response body.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-empty-returns-204\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-400-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST define 400 Bad Request responses with specific and actionable validation error information.\",\r\n      \"relatedAuditItems\": [\r\n        \"400-errors-specific\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-401-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST return 401 Unauthorized for missing or invalid credentials.\",\r\n      \"relatedAuditItems\": [\r\n        \"401-unauthorized\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-403-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST return 403 Forbidden for authenticated clients lacking sufficient permission.\",\r\n      \"relatedAuditItems\": [\r\n        \"403-forbidden\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-VERSION-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"versioning\",\r\n      \"requirement\": \"The REST API MUST define a versioning strategy before production release, and the strategy MUST be supportable by the API gateway.\",\r\n      \"relatedAuditItems\": [\r\n        \"versioning-decided\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST require authentication for protected endpoints.\",\r\n      \"relatedAuditItems\": [\r\n        \"auth-protection\",\r\n        \"401-unauthorized\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST use token-based authentication or another approved modern authentication mechanism for protected endpoints.\",\r\n      \"relatedAuditItems\": [\r\n        \"token-auth\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-03\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST enforce object-level and function-level authorization on every protected operation.\",\r\n      \"relatedAuditItems\": [\r\n        \"401-unauthorized\",\r\n        \"403-forbidden\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-04\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST mitigate OWASP API risks including broken object level authorization, broken function level authorization, injection, and unrestricted resource consumption.\",\r\n      \"relatedAuditItems\": [\r\n        \"auth-protection\",\r\n        \"rate-limits-enforced\",\r\n        \"no-sensitive-data-in-urls\",\r\n        \"message-integrity\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-05\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST use HTTPS or another approved encrypted protocol for all traffic.\",\r\n      \"relatedAuditItems\": [\r\n        \"uses-https\",\r\n        \"encryption-in-transit\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-06\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST NOT expose sensitive information in URLs, query strings, logs, or unnecessary response fields.\",\r\n      \"relatedAuditItems\": [\r\n        \"no-sensitive-data-in-urls\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-07\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API SHOULD use UUIDs or other non-sequential public identifiers where direct database identifiers would increase exposure risk.\",\r\n      \"relatedAuditItems\": [\r\n        \"pseudo-identifiers\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-08\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST implement CSRF protection where relevant to the authentication model and client interaction pattern.\",\r\n      \"relatedAuditItems\": [\r\n        \"csrf-protection\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CAPACITY-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"resilience-capacity\",\r\n      \"requirement\": \"The REST API MUST define and enforce rate limits, throttling, or quotas according to capacity expectations.\",\r\n      \"relatedAuditItems\": [\r\n        \"rate-limits-enforced\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CAPACITY-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"resilience-capacity\",\r\n      \"requirement\": \"The REST API MUST implement resilience controls such as timeouts, fallback behavior, and degradation handling according to business impact.\",\r\n      \"relatedAuditItems\": [\r\n        \"only-via-gateway\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-OBS-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"observability\",\r\n      \"requirement\": \"The REST API MUST implement logs, metrics, and monitoring needed to observe validation failures, auth failures, traffic, latency, and dependency health.\",\r\n      \"relatedAuditItems\": [\r\n        \"rate-limits-enforced\",\r\n        \"message-integrity\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be published through an API management platform.\",\r\n      \"relatedAuditItems\": [\r\n        \"published-via-api-management\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be accessible only through approved API gateway paths and managed entry points.\",\r\n      \"relatedAuditItems\": [\r\n        \"only-via-gateway\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-03\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API SHOULD be visible in a developer portal with documentation generated from the contract.\",\r\n      \"relatedAuditItems\": [\r\n        \"visible-in-dev-portal\",\r\n        \"docs-auto-generated\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-04\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be published under an approved organizational domain.\",\r\n      \"relatedAuditItems\": [\r\n        \"official-domain\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-AUDIT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST validate the specification, schema, and examples on every change.\",\r\n      \"relatedAuditItems\": [\r\n        \"spec-validated-on-change\",\r\n        \"schema-and-examples-pass\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-AUDIT-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST pass concept, design, security, and production-readiness checks before release.\",\r\n      \"relatedAuditItems\": [\r\n        \"concept-items-audited\",\r\n        \"design-items-audited\"\r\n      ]\r\n    }\r\n  ]\r\n}\r\n",
              "draft": false
            },
            {
              "id": "api-compliance-best-practices",
              "slug": "resources/api-compliance-best-practices",
              "title": "API Compliance Best Practices",
              "description": "Ensure APIs meet legal, regulatory, and internal compliance through documentation, controls, and automated validations.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 104,
              "outcomes": [
                "Shared understanding of the purpose and use of API Compliance Best Practices",
                "A consistent approach to applying API Compliance Best Practices",
                "Improved application of the related practices"
              ],
              "steps": [
                "Document compliance measures and ensure they are communicated to stakeholders and consumers.",
                "Implement measures to ensure APIs comply with these requirements, including data encryption, access controls, and audit trails.",
                "Use checklists, linters, and testing tools to verify consistency and conformance with standards."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "service-agreement-template",
              "slug": "resources/service-agreement-template",
              "title": "Service Agreement Template",
              "description": "A customizable agreement format that defines expectations, SLAs, responsibilities, and access terms for API consumption.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 172,
              "outcomes": [
                "Shared understanding of the purpose and use of Service Agreement Template",
                "A consistent approach to applying Service Agreement Template",
                "Improved application of the related practices"
              ],
              "steps": [
                "Define service agreements that outline the expectations, service levels, and responsibilities for each API.",
                "Use standardized formats to create machine-readable service agreements that are easy to share and validate.",
                "Ensure service agreements are reviewed and approved by stakeholders to ensure alignment and clarity."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "api-metrics-and-analytics",
              "slug": "resources/api-metrics-and-analytics",
              "title": "API Metrics And Analytics",
              "description": "A resource for defining, collecting, and analyzing API performance and usage data to align technical KPIs with business outcomes.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 119,
              "outcomes": [
                "Shared understanding of the purpose and use of API Metrics And Analytics",
                "A consistent approach to applying API Metrics And Analytics",
                "Improved application of the related practices"
              ],
              "steps": [
                "Identify key performance indicators (KPIs) to measure API success against business goals.",
                "Define and monitor performance metrics (e.g., API calls, latency, error rates) and adoption metrics (e.g., NPS).",
                "Monitor API initiatives to ensure adherence to operating guidelines and governance practices"
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            },
            {
              "id": "api-community-engagement-strategies",
              "slug": "resources/api-community-engagement-strategies",
              "title": "API Community Engagement Strategies",
              "description": "A playbook for fostering API adoption by cultivating communities through content, support channels, feedback loops, and social engagement strategies.",
              "category": "guideline",
              "icon": "edit-document-outline",
              "order": 103,
              "outcomes": [
                "Shared understanding of the purpose and use of API Community Engagement Strategies",
                "A consistent approach to applying API Community Engagement Strategies",
                "Improved application of the related practices"
              ],
              "steps": [
                "Develop marketing strategies to promote APIs to target audiences, including social media, blogs, and webinars.",
                "Create promotional materials (e.g., case studies, success stories) that highlight the value and benefits of APIs.",
                "Create educational materials (e.g., tutorials, documentation) that explain API features, benefits, and usage patterns.",
                "Engage with API consumers through feedback loops, support channels, and community forums to understand their needs and improve API adoption.",
                "Analyze API usage metrics and incorporate user feedback into API iterations."
              ],
              "canvasId": null,
              "sourcePath": null,
              "sourceUrl": null,
              "contentMarkdown": null,
              "draft": true
            }
          ],
          "promptIds": [
            "operations-specialist:facilitate-station",
            "operations-specialist:use-resources",
            "operations-specialist:next-actions"
          ]
        }
      ],
      "resources": [
        {
          "id": "customerJourneyCanvas",
          "slug": "resources/customer-journey-canvas",
          "title": "Customer Journey Canvas",
          "description": "Map customer, partner, or consumer journeys to identify needs, pain points, gains, inputs, outputs, and experience expectations.",
          "category": "canvas",
          "icon": "dashboard-outline",
          "order": 1,
          "outcomes": [
            "Shared understanding of the customer, partner, or consumer journey",
            "Needs, pain points, gains, inputs, and outputs documented",
            "Journey evidence available for capability, requirements, and architecture decisions"
          ],
          "steps": [
            "Define customer persona",
            "Identify triggers for the journey",
            "Describe the journey's end",
            "Map journey steps with inputs/outputs",
            "Identify customer pains",
            "Summarize customer gains",
            "Define necessary inputs and resulting outputs",
            "Define interactions and processing expectations for each step"
          ],
          "canvasId": "customerJourneyCanvas",
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": false
        },
        {
          "id": "apiValuePropositionCanvas",
          "slug": "resources/api-value-proposition-canvas",
          "title": "API Value Proposition Canvas",
          "description": "Align API features with user needs by mapping tasks, pains, and gains to API products.",
          "category": "canvas",
          "icon": "dashboard-outline",
          "order": 2,
          "outcomes": [
            "Focused feature development",
            "Alignment with user needs",
            "Improved API consumer satisfaction"
          ],
          "steps": [
            "List user journey tasks",
            "Identify features delivering expected gains",
            "Define features addressing challenges",
            "Map features to API products"
          ],
          "canvasId": "apiValuePropositionCanvas",
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": false
        },
        {
          "id": "capabilityValuePropositionCanvas",
          "slug": "resources/capability-value-proposition-canvas",
          "title": "Capability Value Proposition Canvas",
          "description": "A technology-agnostic canvas for mapping consumer tasks, gains, pains, and candidate reusable capabilities before selecting an implementation style.",
          "category": "canvas",
          "icon": "dashboard-outline",
          "order": 2.1,
          "outcomes": [
            "Clear reusable capability value proposition",
            "Consumer tasks, gains, and pains captured without assuming a technology",
            "Candidate reusable capabilities identified for architecture evaluation"
          ],
          "steps": [
            "List the consumer tasks and outcomes the capability should support.",
            "Identify gain-enabling capability features.",
            "Identify pain-relieving capability features.",
            "Group the features into candidate reusable capabilities."
          ],
          "canvasId": "capabilityValuePropositionCanvas",
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": false
        },
        {
          "id": "apiBusinessModelCanvas",
          "slug": "resources/api-business-model-canvas",
          "title": "API Business Model Canvas",
          "description": "Strategically assess API business viability by mapping value propositions, consumer segments, and key resources.",
          "category": "canvas",
          "icon": "dashboard-outline",
          "order": 3,
          "outcomes": [
            "Clear business strategy for APIs",
            "Identification of key resources and partners",
            "Alignment of API features with business goals"
          ],
          "steps": [
            "Summarize the API's value proposition",
            "Define consumer segments",
            "Identify developer relations strategies",
            "Map distribution channels",
            "Document key resources and activities",
            "Identify key partners and stakeholders",
            "Highlight benefits and costs"
          ],
          "canvasId": "apiBusinessModelCanvas",
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": false
        },
        {
          "id": "capabilityBusinessModelCanvas",
          "slug": "resources/capability-business-model-canvas",
          "title": "Capability Business Model Canvas",
          "description": "A business model canvas for reusable capabilities, covering value, consumers, ownership, engagement, costs, and benefits without assuming an implementation style.",
          "category": "canvas",
          "icon": "dashboard-outline",
          "order": 3.1,
          "outcomes": [
            "Viable reusable capability operating model",
            "Ownership, consumers, channels, partners, and support needs clarified",
            "Costs and benefits visible before architecture commitment"
          ],
          "steps": [
            "Summarize the capability value proposition.",
            "Identify consumer segments and engagement channels.",
            "Define key activities, resources, and partners.",
            "Capture costs and benefits.",
            "Clarify ownership, funding, support, and lifecycle expectations.",
            "Validate the model with consumers, producers, and governance stakeholders."
          ],
          "canvasId": "capabilityBusinessModelCanvas",
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": false
        },
        {
          "id": "consumerExperienceRequirementsCanvas",
          "slug": "resources/consumer-experience-requirements-canvas",
          "title": "Consumer Experience Requirements Canvas",
          "description": "A requirements canvas for consumer experience and non-functional needs that should guide the later architecture and implementation-style decision.",
          "category": "canvas",
          "icon": "dashboard-outline",
          "order": 3.2,
          "outcomes": [
            "Technology-agnostic consumer and service requirements",
            "Experience and non-functional needs captured before design starts",
            "Architecture implications documented for implementation-style selection"
          ],
          "steps": [
            "Capture consumer goals and usage context.",
            "Document availability, timeliness, volume, performance, data quality, and consistency expectations.",
            "Document security, privacy, onboarding, change, observability, support, and recovery expectations.",
            "Summarize what the requirements imply for possible implementation styles."
          ],
          "canvasId": "consumerExperienceRequirementsCanvas",
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": false
        },
        {
          "id": "businessImpactCanvas",
          "slug": "resources/business-impact-canvas",
          "title": "Business Impact Canvas",
          "description": "Identify business, availability, security, data, compliance, and operational risks that should shape architecture and platform decisions.",
          "category": "canvas",
          "icon": "dashboard-outline",
          "order": 4,
          "outcomes": [
            "Documented business and operational impact assessment",
            "Prioritized risks and mitigation actions",
            "Evidence for architecture and platform decisions"
          ],
          "steps": [
            "Availability Risks: Identify risks and impacts.",
            "Ways to Mitigate Availability Risks: Define mitigation measures.",
            "Security Risks: Document security-related risks.",
            "Ways to Mitigate Security Risks: Propose strategies to mitigate security risks.",
            "Data Risks: Identify risks to data accuracy or availability.",
            "Ways to Mitigate Data Risks: Plan strategies to address data risks."
          ],
          "canvasId": "businessImpactCanvas",
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": false
        },
        {
          "id": "locationsCanvas",
          "slug": "resources/location-canvas",
          "title": "Location Canvas",
          "description": "Map consumer, producer, system, data, network, regulatory, and trust-boundary locations to ensure compliance and performance across regions.",
          "category": "canvas",
          "icon": "dashboard-outline",
          "order": 6,
          "outcomes": [
            "Documented location, residency, network, and regulatory requirements",
            "Regional performance and accessibility constraints identified",
            "Data residency, trust boundaries, and applicable regulations clarified"
          ],
          "steps": [
            "Map locations of producers, source systems, platforms, and consumers.",
            "Document where consumers are located.",
            "Identify applicable regulations.",
            "Document where data must reside.",
            "Ensure the capability is accessible in all intended network regions.",
            "Validate network performance across regions."
          ],
          "canvasId": "locationsCanvas",
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": false
        },
        {
          "id": "capacityCanvas",
          "slug": "resources/capacity-canvas",
          "title": "Capacity Canvas",
          "description": "Plan capacity for current and future demand, including volumes, peaks, latency, availability, scaling, caching, and rate limits for the selected capability and implementation style.",
          "category": "canvas",
          "icon": "dashboard-outline",
          "order": 7,
          "outcomes": [
            "Capacity requirements aligned with expected business demand",
            "Peak-load, availability, and growth assumptions documented",
            "Scaling, caching, and rate-limiting decisions defined"
          ],
          "steps": [
            "Document current business volumes",
            "Forecast future consumption trends",
            "Plan for peak load and availability requirements",
            "Define caching and rate-limiting strategies",
            "Propose scaling strategies"
          ],
          "canvasId": "capacityCanvas",
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": false
        },
        {
          "id": "interactionCanvas",
          "slug": "resources/interaction-canvas",
          "title": "Interaction Canvas",
          "description": "Define interactions, workflows, inputs, outputs, commands, queries, events, and expected responses to ensure a consistent consumer experience.",
          "category": "canvas",
          "icon": "dashboard-outline",
          "order": 9,
          "outcomes": [
            "Defined interaction model for the selected capability",
            "Inputs, outputs, commands, queries, events, and responses clarified",
            "Validation rules and interaction expectations agreed"
          ],
          "steps": [
            "Map interactions to user, consumer, or system tasks",
            "Define access points, operations, commands, queries, or events for each interaction",
            "Document inputs and outputs for each interaction.",
            "Specify validation rules and constraints",
            "Create interaction models for CRUD, query-driven, command-driven, and event-driven interactions"
          ],
          "canvasId": "interactionCanvas",
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": false
        },
        {
          "id": "restCanvas",
          "slug": "resources/rest-canvas",
          "title": "REST Canvas",
          "description": "Design APIs using RESTful principles, defining resources, verbs, and example requests and responses.",
          "category": "canvas",
          "icon": "dashboard-outline",
          "order": 10,
          "outcomes": [
            "Consistent RESTful API design",
            "Defined resources and their interactions",
            "Example requests and responses for clarity"
          ],
          "steps": [
            "Identify key resources exposed by the API",
            "Define the structure of the API resource model",
            "Specify HTTP verbs used to interact with resources",
            "Provide example requests and responses for each verb"
          ],
          "canvasId": "restCanvas",
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": false
        },
        {
          "id": "graphqlCanvas",
          "slug": "resources/graphql-canvas",
          "title": "GraphQL Canvas",
          "description": "Design GraphQL APIs by defining types, queries, mutations, and subscriptions.",
          "category": "canvas",
          "icon": "dashboard-outline",
          "order": 11,
          "outcomes": [
            "Structured GraphQL API design",
            "Defined types and their relationships",
            "Clear queries, mutations, and subscriptions"
          ],
          "steps": [
            "What problems are API consumers trying to solve? What data do they need?",
            "Define GraphQL types and their attributes: What are the core types exposed (e.g., User, Order, Product)?",
            "Map relationships between types: How do types relate to each other in nested queries?",
            "Specify queries for data retrieval",
            "Define mutations for data modification: What operations will modify data (e.g., create, update, delete)?",
            "Outline subscriptions for real-time updates",
            "Define authentication and authorization: Who can access which fields or types?",
            "Consider if there are any pagination, filtering, or rate-limiting constraints"
          ],
          "canvasId": "graphqlCanvas",
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": true
        },
        {
          "id": "eventCanvas",
          "slug": "resources/event-canvas",
          "title": "Event Canvas",
          "description": "Design event-driven interfaces and integrations by defining events, triggers, schemas, producers, consumers, and processing logic.",
          "category": "canvas",
          "icon": "dashboard-outline",
          "order": 12,
          "outcomes": [
            "Defined event-driven interaction model",
            "Events, triggers, schemas, producers, and consumers clarified",
            "Processing, acknowledgement, and failure expectations documented"
          ],
          "steps": [
            "Identify key events in the system",
            "Define triggers for each event",
            "Describe event processing, state changes, and failure handling.",
            "Specify resulting outputs or acknowledgments"
          ],
          "canvasId": "eventCanvas",
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": false
        },
        {
          "id": "api-audit-checklist",
          "slug": "resources/api-audit-checklist",
          "title": "API Audit Checklist",
          "description": "A lifecycle-based checklist to verify API readiness across design, delivery, publishing, and compliance using defined audit criteria and evidence.",
          "category": "checklist",
          "icon": "check-box-outline",
          "order": 13,
          "outcomes": [
            "Shared understanding of the purpose and use of API Audit Checklist",
            "A consistent approach to applying API Audit Checklist",
            "Improved application of the related practices"
          ],
          "steps": [
            "Use the API Audit Checklist to ensure the API design meets functional and non-functional requirements, including security, performance, and compliance.",
            "Conduct audits to assess lifecycle coverage and verify that the API meets business, design, and operational standards.",
            "Ensure that documentation, security models, gateway configuration, and legal requirements are clearly defined, validated, and supported by evidence."
          ],
          "canvasId": null,
          "sourcePath": "src/snippets/api-audit-checklist.json",
          "sourceUrl": null,
          "contentMarkdown": "{\r\n  \"profiles\": {\r\n    \"read-only\": {\r\n      \"description\": \"API profile that is read-only and does not allow create, update, or delete operations.\"\r\n    },\r\n    \"full-crud\": {\r\n      \"description\": \"General API profile that allows create, update, and delete operations.\"\r\n    }\r\n  },\r\n  \"lifecycleStages\": [\r\n    {\r\n      \"id\": \"strategy\",\r\n      \"title\": \"Strategy\",\r\n      \"readinessLabel\": \"Strategy is Ready When...\",\r\n      \"order\": 1\r\n    },\r\n    {\r\n      \"id\": \"architecture\",\r\n      \"title\": \"Architecture\",\r\n      \"readinessLabel\": \"Architecture is Ready When...\",\r\n      \"order\": 2\r\n    },\r\n    {\r\n      \"id\": \"design\",\r\n      \"title\": \"Design\",\r\n      \"readinessLabel\": \"Design is Ready When...\",\r\n      \"order\": 3\r\n    },\r\n    {\r\n      \"id\": \"delivery\",\r\n      \"title\": \"Delivery\",\r\n      \"readinessLabel\": \"Delivery is Ready When...\",\r\n      \"order\": 4\r\n    },\r\n    {\r\n      \"id\": \"publishing\",\r\n      \"title\": \"Publishing\",\r\n      \"readinessLabel\": \"Publishing is Ready When...\",\r\n      \"order\": 5\r\n    },\r\n    {\r\n      \"id\": \"improving\",\r\n      \"title\": \"Improving\",\r\n      \"readinessLabel\": \"Improving is Ready When...\",\r\n      \"order\": 6\r\n    }\r\n  ],\r\n  \"stages\": [\r\n    {\r\n      \"id\": \"strategy\",\r\n      \"title\": \"Strategy\",\r\n      \"readinessLabel\": \"Strategy is Ready When...\",\r\n      \"order\": 1,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"based-on-clear-business-needs\",\r\n          \"label\": \"API is based on clear business needs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"strategy\",\r\n          \"producedByStation\": [\r\n            \"api-product-strategy\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"business-goals-defined\",\r\n            \"market-research-done\",\r\n            \"stakeholder-approval\",\r\n            \"metrics-feedback-available\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DOMAIN-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiBusinessModelCanvas\",\r\n            \"apiValuePropositionCanvas\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"design-artifact\",\r\n            \"documentation\",\r\n            \"research\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-product-strategy/apiValuePropositionCanvas.empty.json\",\r\n            \"specs/canvases/api-product-strategy/apiBusinessModelCanvas.empty.json\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"concept-items-audited\",\r\n          \"label\": \"All concept checklist items are audited\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"aggregate\",\r\n          \"check\": {\r\n            \"type\": \"stageCoverage\",\r\n            \"stageId\": \"strategy\"\r\n          },\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"strategy\",\r\n          \"producedByStation\": [\r\n            \"api-product-strategy\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"business-goals-defined\",\r\n            \"market-research-done\",\r\n            \"stakeholder-approval\",\r\n            \"metrics-feedback-available\",\r\n            \"api-opportunity-documented\",\r\n            \"api-reusability\",\r\n            \"value-prop-validated\",\r\n            \"consumer-segments-identified\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"report\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"audit/concept-review-report.json\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"architecture\",\r\n      \"title\": \"Architecture\",\r\n      \"readinessLabel\": \"Architecture is Ready When...\",\r\n      \"order\": 2,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"versioning-decided\",\r\n          \"label\": \"Versioning strategy decided and supported by gateway\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"architecture\",\r\n          \"producedByStation\": [\r\n            \"api-platform-architecture\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-roadmap-defined\",\r\n            \"api-reusability\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-VERSION-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"contract-first-design\",\r\n            \"api-versioning-best-practices\",\r\n            \"apiops-CI-CD-for-apis\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"ci-cd\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"docs/api/architecture/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"only-via-gateway\",\r\n          \"label\": \"Only accessible via API gateway\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"architecture\",\r\n          \"producedByStation\": [\r\n            \"api-platform-architecture\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-reusability\",\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-02\",\r\n            \"REST-CAPACITY-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"businessImpactCanvas\",\r\n            \"locationsCanvas\",\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"gateway-config\",\r\n            \"infra-config\",\r\n            \"security-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/architecture/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"rate-limits-enforced\",\r\n          \"label\": \"Rate limits are enforced\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"architecture\",\r\n          \"producedByStation\": [\r\n            \"api-platform-architecture\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-roadmap-defined\",\r\n            \"api-reusability\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CAPACITY-01\",\r\n            \"REST-OBS-01\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"capacityCanvas\",\r\n            \"api-security-best-practices\",\r\n            \"scalable-infrastructure-best-practices\",\r\n            \"api-metrics-and-analytics\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"gateway-config\",\r\n            \"runtime\",\r\n            \"monitoring\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-platform-architecture/capacityCanvas.empty.json\",\r\n            \"docs/api/architecture/README.md\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"design\",\r\n      \"title\": \"Design\",\r\n      \"readinessLabel\": \"Design is Ready When...\",\r\n      \"order\": 3,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"endpoint-descriptions-present\",\r\n          \"label\": \"Endpoints have business value and feature descriptions\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"operationDescriptions\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"value-prop-validated\",\r\n            \"api-opportunity-documented\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CX-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiValuePropositionCanvas\",\r\n            \"customerJourneyCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"design-artifact\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"specs/canvases/api-product-strategy/apiValuePropositionCanvas.empty.json\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"hides-raw-backend-data\",\r\n          \"label\": \"API hides raw backend data and is designed for shared use\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"hide-backend-discrepancies\",\r\n            \"design-reflects-business-value\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DOMAIN-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"interactionCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"design-artifact\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-product-strategy/domainCanvas.empty.json\",\r\n            \"specs/canvases/api-design/interactionCanvas.empty.json\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"design-consistent\",\r\n          \"label\": \"API design is consistent with other APIs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-platform-architecture\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"architecture-patterns-validated\",\r\n            \"api-reusability\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DOMAIN-02\",\r\n            \"REST-CX-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"documentation\",\r\n            \"design-artifact\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/canvases/api-design/restCanvas.empty.json\",\r\n            \"docs/api/design/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"descriptive-english-naming\",\r\n          \"label\": \"Data and attribute naming uses descriptive English\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"fieldNamesDescriptive\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-NAMING-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"mandatory-fields-specified\",\r\n          \"label\": \"Mandatory fields are specified\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"requiredFieldsPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-VALIDATION-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"contract\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"dates-use-iso\",\r\n          \"label\": \"Dates use ISO format with timezone\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"dateFormatTimezone\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DATA-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"general-data-uses-standard-values\",\r\n          \"label\": \"General data uses standard values\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"standardizedEnumsOrPatterns\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"design-reflects-business-value\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-DATA-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"field-names-avoid-acronyms\",\r\n          \"label\": \"Field names avoid acronyms and use full words\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"avoidAcronyms\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-NAMING-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"create-returns-identifiers\",\r\n          \"label\": \"Creating new resources returns identifiers\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is read-only and does not create resources.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-201-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"paths-max-two-resources\",\r\n          \"label\": \"Endpoint paths contain max two resources or sub-resources\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"pathDepthMax\",\r\n            \"maxDepth\": 2\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PATH-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"examples-present\",\r\n          \"label\": \"Endpoints and attributes include examples\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"examplesPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CX-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"restCanvas\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"post-for-create-update\",\r\n          \"label\": \"POST is used for create or update\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose create or update operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"design-reflects-business-value\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-POST-01\",\r\n            \"REST-HTTP-PUT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"delete-for-remove\",\r\n          \"label\": \"DELETE is used to remove resources\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose delete operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-DELETE-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"get-no-request-body\",\r\n          \"label\": \"GET has no request body and returns content\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"getNoRequestBody\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-GET-01\",\r\n            \"REST-RESP-200-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"get-empty-returns-204\",\r\n          \"label\": \"GET returns 204 if response body is empty\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"The current contract returns content for all GET operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-204-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"post-returns-200\",\r\n          \"label\": \"POST returns 200 OK when updating\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose POST updates.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-200-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"post-returns-201\",\r\n          \"label\": \"POST returns 201 Created with ID on create\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose POST creates.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-201-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"delete-returns-204\",\r\n          \"label\": \"DELETE returns 204 on success\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"Read-only profile does not expose DELETE operations.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-RESP-204-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-onboarding-best-practices\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"400-errors-specific\",\r\n          \"label\": \"400 errors provide specific error information\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"errorResponsesSpecific\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-consumer-experience\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"design-reflects-business-value\",\r\n            \"api-consistency\",\r\n            \"value-prop-validated\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-ERROR-400-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"restCanvas\",\r\n            \"api-audit-checklist\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"401-unauthorized\",\r\n          \"label\": \"401 Unauthorized for wrong credentials\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"The current public storefront contract is intentionally unauthenticated.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-ERROR-401-01\",\r\n            \"REST-SEC-01\",\r\n            \"REST-SEC-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"security-config\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"403-forbidden\",\r\n          \"label\": \"403 Forbidden for unauthorized operations\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"The current profile is public read-only and exposes no unauthorized operations.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-ERROR-403-01\",\r\n            \"REST-SEC-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"security-config\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"spec-contains-schemas\",\r\n          \"label\": \"Spec contains request and response schema\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"schemasPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CONTRACT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"contract-first-design\",\r\n            \"restCanvas\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"contract\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"pseudo-identifiers\",\r\n          \"label\": \"UUIDs or pseudo-identifiers instead of DB IDs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"opaqueIdentifiers\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"hide-backend-discrepancies\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-07\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"domainCanvas\",\r\n            \"contract-first-design\",\r\n            \"api-security-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"no-sensitive-data-in-urls\",\r\n          \"label\": \"No sensitive data in URLs\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"noSensitiveDataInPaths\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"hide-backend-discrepancies\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-06\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"contract-first-design\",\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"http-methods-match-resources\",\r\n          \"label\": \"HTTP methods only for intended resources\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"methodResourceConsistency\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"design\",\r\n          \"producedByStation\": [\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-HTTP-GET-01\",\r\n            \"REST-HTTP-POST-01\",\r\n            \"REST-HTTP-PUT-01\",\r\n            \"REST-HTTP-DELETE-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"restCanvas\",\r\n            \"api-design-principles\",\r\n            \"contract-first-design\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"delivery\",\r\n      \"title\": \"Delivery\",\r\n      \"readinessLabel\": \"Delivery is Ready When...\",\r\n      \"order\": 4,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"design-items-audited\",\r\n          \"label\": \"All prototype and design items are audited\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"aggregate\",\r\n          \"check\": {\r\n            \"type\": \"stageCoverage\",\r\n            \"stageId\": \"design\"\r\n          },\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-design\",\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"design-reflects-business-value\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"report\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"audit/production-readiness-review.json\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"spec-validated-on-change\",\r\n          \"label\": \"Spec validated on every change\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"validationWorkflowPresent\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-audit-checklist\",\r\n            \"contract-first-design\",\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"api-testing-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"ci-cd\",\r\n            \"spec\",\r\n            \"test\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \".github/workflows/openapi-lint.yml\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"schema-and-examples-pass\",\r\n          \"label\": \"Schema and examples pass validation\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"openapi\",\r\n          \"check\": {\r\n            \"type\": \"examplesPassValidation\"\r\n          },\r\n          \"automationLevel\": \"auto\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-design\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-consistency\",\r\n            \"architecture-patterns-validated\",\r\n            \"api-contract-tested\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-AUDIT-01\",\r\n            \"REST-CONTRACT-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"contract-first-design\",\r\n            \"api-audit-checklist\",\r\n            \"api-testing-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"test\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"uses-https\",\r\n          \"label\": \"Uses HTTPS or encrypted protocols\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-05\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"gateway-config\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"auth-protection\",\r\n          \"label\": \"Endpoints protected by authentication\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is intentionally public read-only.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-01\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"gateway-config\",\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"token-auth\",\r\n          \"label\": \"Token-based authentication\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is intentionally public read-only.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"csrf-protection\",\r\n          \"label\": \"Protected against CSRF\",\r\n          \"applicableTo\": [\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"This profile is intentionally public read-only.\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-08\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-development-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"code\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"inputs-auto-validated\",\r\n          \"label\": \"Inputs auto-validated by framework\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-VALIDATION-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-development-best-practices\",\r\n            \"contract-first-design\",\r\n            \"api-testing-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"code\",\r\n            \"test\",\r\n            \"spec\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"docs/api/delivery/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"outputs-auto-escaped\",\r\n          \"label\": \"Outputs auto-escaped by framework\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"n/a\",\r\n          \"defaultStatus\": \"na\",\r\n          \"reason\": \"JSON APIs do not typically require output escaping in the same way as HTML rendering.\",\r\n          \"automationLevel\": \"manual\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-development-best-practices\",\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"code\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"encryption-in-transit\",\r\n          \"label\": \"Encryption for data in transit and storage\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\",\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-SEC-05\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"data-privacy-guidelines\",\r\n            \"api-compliance-best-practices\",\r\n            \"api-metrics-and-analytics\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"infra-config\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"message-integrity\",\r\n          \"label\": \"Message integrity implemented\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"delivery\",\r\n          \"producedByStation\": [\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"architecture-patterns-validated\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-OBS-01\",\r\n            \"REST-SEC-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-security-best-practices\",\r\n            \"api-compliance-best-practices\",\r\n            \"api-metrics-and-analytics\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"security-config\",\r\n            \"monitoring\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/delivery/README.md\",\r\n            \"docs/api/architecture/README.md\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"publishing\",\r\n      \"title\": \"Publishing\",\r\n      \"readinessLabel\": \"Publishing is Ready When...\",\r\n      \"order\": 5,\r\n      \"items\": [\r\n        {\r\n          \"id\": \"published-via-api-management\",\r\n          \"label\": \"Published via API management\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-01\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"api-onboarding-best-practices\",\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"gateway-config\",\r\n            \"ci-cd\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \".github/workflows/openapi-lint.yml\",\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"visible-in-dev-portal\",\r\n          \"label\": \"Visible in developer portal\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-documentation-ready\",\r\n            \"api-ready-for-publishing\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"api-community-engagement-strategies\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"documentation\",\r\n            \"runtime\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"docs-auto-generated\",\r\n          \"label\": \"Docs auto-generated from spec and schema\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"partial\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\",\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-documentation-ready\",\r\n            \"api-ready-for-publishing\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CONTRACT-02\",\r\n            \"REST-PUBLISH-03\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"contract-first-design\",\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"api-onboarding-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"spec\",\r\n            \"documentation\",\r\n            \"ci-cd\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"specs/openapi/api.yaml\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"docs/api/audit/design-audit.read-only.md\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"spec-auto-updated\",\r\n          \"label\": \"Spec auto-updated to gateway and dev portal\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\",\r\n            \"api-delivery\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\",\r\n            \"api-consistency\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-CONTRACT-02\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"apiops-CI-CD-for-apis\",\r\n            \"contract-first-design\",\r\n            \"api-onboarding-best-practices\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"ci-cd\",\r\n            \"gateway-config\",\r\n            \"documentation\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \".github/workflows/openapi-lint.yml\",\r\n            \"docs/api/publishing/README.md\",\r\n            \"specs/openapi/api.yaml\"\r\n          ]\r\n        },\r\n        {\r\n          \"id\": \"official-domain\",\r\n          \"label\": \"Published under official organization domain\",\r\n          \"applicableTo\": [\r\n            \"read-only\",\r\n            \"full-crud\"\r\n          ],\r\n          \"kind\": \"manual\",\r\n          \"defaultStatus\": \"gap\",\r\n          \"automationLevel\": \"semi\",\r\n          \"primaryStage\": \"publishing\",\r\n          \"producedByStation\": [\r\n            \"api-publishing\"\r\n          ],\r\n          \"producedByStationCriteria\": [\r\n            \"api-ready-for-publishing\",\r\n            \"audit-passed\"\r\n          ],\r\n          \"guidelines\": [\r\n            \"REST-PUBLISH-04\"\r\n          ],\r\n          \"resourceSource\": [\r\n            \"api-onboarding-best-practices\",\r\n            \"api-audit-checklist\"\r\n          ],\r\n          \"expectedEvidenceTags\": [\r\n            \"documentation\",\r\n            \"runtime\"\r\n          ],\r\n          \"expectedEvidence\": [\r\n            \"docs/api/publishing/README.md\"\r\n          ]\r\n        }\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"improving\",\r\n      \"title\": \"Improving\",\r\n      \"readinessLabel\": \"Improving is Ready When...\",\r\n      \"order\": 6,\r\n      \"items\": []\r\n    }\r\n  ],\r\n  \"guidelines\": [\r\n    {\r\n      \"id\": \"REST-CONTRACT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST implement endpoints, parameters, request bodies, response bodies, and error responses as defined in the validated OpenAPI contract.\",\r\n      \"relatedAuditItems\": [\r\n        \"spec-contains-schemas\",\r\n        \"schema-and-examples-pass\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CONTRACT-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST keep the implementation, published OpenAPI description, gateway configuration, and developer portal documentation aligned on every change.\",\r\n      \"relatedAuditItems\": [\r\n        \"docs-auto-generated\",\r\n        \"spec-auto-updated\",\r\n        \"spec-validated-on-change\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-VALIDATION-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST validate path parameters, query parameters, headers, and JSON request bodies against the OpenAPI schema before business processing.\",\r\n      \"relatedAuditItems\": [\r\n        \"mandatory-fields-specified\",\r\n        \"400-errors-specific\",\r\n        \"inputs-auto-validated\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DOMAIN-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST expose business-oriented resources and attributes rather than raw backend tables, internal service payloads, or system-specific field names.\",\r\n      \"relatedAuditItems\": [\r\n        \"based-on-clear-business-needs\",\r\n        \"hides-raw-backend-data\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DOMAIN-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST preserve validated meanings of entities, attributes, statuses, and source-of-truth rules across all endpoints and operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"design-consistent\",\r\n        \"general-data-uses-standard-values\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-NAMING-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST use descriptive English names for resources and attributes.\",\r\n      \"relatedAuditItems\": [\r\n        \"descriptive-english-naming\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-NAMING-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST avoid unexplained acronyms in public field and resource names.\",\r\n      \"relatedAuditItems\": [\r\n        \"field-names-avoid-acronyms\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DATA-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST use ISO date-time values with timezone information where dates are exposed.\",\r\n      \"relatedAuditItems\": [\r\n        \"dates-use-iso\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DATA-02\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API SHOULD use standard codes, controlled vocabularies, and standardized value sets where applicable.\",\r\n      \"relatedAuditItems\": [\r\n        \"general-data-uses-standard-values\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API MUST describe the business value and feature intent of each endpoint or capability.\",\r\n      \"relatedAuditItems\": [\r\n        \"endpoint-descriptions-present\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API MUST include examples for endpoints, request bodies, response bodies, and key attributes.\",\r\n      \"relatedAuditItems\": [\r\n        \"examples-present\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-03\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API SHOULD use consistent pagination, filtering, sorting, and response conventions across resources.\",\r\n      \"relatedAuditItems\": [\r\n        \"design-consistent\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-GET-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use GET for safe read-only operations and MUST NOT define a request body for GET operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-no-request-body\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-POST-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use POST for resource creation and other non-idempotent operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"post-for-create-update\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-PUT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use PUT only for full resource replacement.\",\r\n      \"relatedAuditItems\": [\r\n        \"post-for-create-update\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-DELETE-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use DELETE to remove resources.\",\r\n      \"relatedAuditItems\": [\r\n        \"delete-for-remove\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PATH-01\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"resource-modeling\",\r\n      \"requirement\": \"The REST API SHOULD keep endpoint paths shallow and avoid more than two resource or sub-resource levels unless explicitly justified.\",\r\n      \"relatedAuditItems\": [\r\n        \"paths-max-two-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-200-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 200 OK for successful reads and updates that include a response body.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-no-request-body\",\r\n        \"post-returns-200\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-201-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 201 Created and the created resource identifier when a new resource is created.\",\r\n      \"relatedAuditItems\": [\r\n        \"create-returns-identifiers\",\r\n        \"post-returns-201\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-204-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 204 No Content for successful delete operations that do not return a body.\",\r\n      \"relatedAuditItems\": [\r\n        \"delete-returns-204\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-204-02\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API SHOULD return 204 No Content for successful operations that intentionally return no response body.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-empty-returns-204\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-400-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST define 400 Bad Request responses with specific and actionable validation error information.\",\r\n      \"relatedAuditItems\": [\r\n        \"400-errors-specific\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-401-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST return 401 Unauthorized for missing or invalid credentials.\",\r\n      \"relatedAuditItems\": [\r\n        \"401-unauthorized\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-403-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST return 403 Forbidden for authenticated clients lacking sufficient permission.\",\r\n      \"relatedAuditItems\": [\r\n        \"403-forbidden\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-VERSION-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"versioning\",\r\n      \"requirement\": \"The REST API MUST define a versioning strategy before production release, and the strategy MUST be supportable by the API gateway.\",\r\n      \"relatedAuditItems\": [\r\n        \"versioning-decided\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST require authentication for protected endpoints.\",\r\n      \"relatedAuditItems\": [\r\n        \"auth-protection\",\r\n        \"401-unauthorized\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST use token-based authentication or another approved modern authentication mechanism for protected endpoints.\",\r\n      \"relatedAuditItems\": [\r\n        \"token-auth\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-03\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST enforce object-level and function-level authorization on every protected operation.\",\r\n      \"relatedAuditItems\": [\r\n        \"401-unauthorized\",\r\n        \"403-forbidden\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-04\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST mitigate OWASP API risks including broken object level authorization, broken function level authorization, injection, and unrestricted resource consumption.\",\r\n      \"relatedAuditItems\": [\r\n        \"auth-protection\",\r\n        \"rate-limits-enforced\",\r\n        \"no-sensitive-data-in-urls\",\r\n        \"message-integrity\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-05\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST use HTTPS or another approved encrypted protocol for all traffic.\",\r\n      \"relatedAuditItems\": [\r\n        \"uses-https\",\r\n        \"encryption-in-transit\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-06\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST NOT expose sensitive information in URLs, query strings, logs, or unnecessary response fields.\",\r\n      \"relatedAuditItems\": [\r\n        \"no-sensitive-data-in-urls\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-07\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API SHOULD use UUIDs or other non-sequential public identifiers where direct database identifiers would increase exposure risk.\",\r\n      \"relatedAuditItems\": [\r\n        \"pseudo-identifiers\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-08\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST implement CSRF protection where relevant to the authentication model and client interaction pattern.\",\r\n      \"relatedAuditItems\": [\r\n        \"csrf-protection\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CAPACITY-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"resilience-capacity\",\r\n      \"requirement\": \"The REST API MUST define and enforce rate limits, throttling, or quotas according to capacity expectations.\",\r\n      \"relatedAuditItems\": [\r\n        \"rate-limits-enforced\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CAPACITY-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"resilience-capacity\",\r\n      \"requirement\": \"The REST API MUST implement resilience controls such as timeouts, fallback behavior, and degradation handling according to business impact.\",\r\n      \"relatedAuditItems\": [\r\n        \"only-via-gateway\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-OBS-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"observability\",\r\n      \"requirement\": \"The REST API MUST implement logs, metrics, and monitoring needed to observe validation failures, auth failures, traffic, latency, and dependency health.\",\r\n      \"relatedAuditItems\": [\r\n        \"rate-limits-enforced\",\r\n        \"message-integrity\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be published through an API management platform.\",\r\n      \"relatedAuditItems\": [\r\n        \"published-via-api-management\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be accessible only through approved API gateway paths and managed entry points.\",\r\n      \"relatedAuditItems\": [\r\n        \"only-via-gateway\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-03\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API SHOULD be visible in a developer portal with documentation generated from the contract.\",\r\n      \"relatedAuditItems\": [\r\n        \"visible-in-dev-portal\",\r\n        \"docs-auto-generated\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-04\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be published under an approved organizational domain.\",\r\n      \"relatedAuditItems\": [\r\n        \"official-domain\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-AUDIT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST validate the specification, schema, and examples on every change.\",\r\n      \"relatedAuditItems\": [\r\n        \"spec-validated-on-change\",\r\n        \"schema-and-examples-pass\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-AUDIT-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST pass concept, design, security, and production-readiness checks before release.\",\r\n      \"relatedAuditItems\": [\r\n        \"concept-items-audited\",\r\n        \"design-items-audited\"\r\n      ]\r\n    }\r\n  ]\r\n}\r\n",
          "draft": false
        },
        {
          "id": "api-design-principles",
          "slug": "resources/api-design-principles",
          "title": "API Design Principles",
          "description": "A concise guide to API usability, discoverability, and consistency grounded in shared design rules and real consumer needs.",
          "category": "guideline",
          "icon": "edit-document-outline",
          "order": 14,
          "outcomes": [
            "Shared understanding of the purpose and use of API Design Principles",
            "A consistent approach to applying API Design Principles",
            "Improved application of the related practices"
          ],
          "steps": [
            "**Consumer-first design:** start every APIOps cycle by gathering user goals and domain terms so APIs solve real problems.",
            "**Consistent naming and behavior:** apply shared conventions for resources, errors and formats to make APIs predictable.",
            "**Contract driven:** capture the interface with OpenAPI or AsyncAPI before coding to align teams and enable automation.",
            "**Usability and discoverability:** provide clear documentation and examples so developers quickly understand how to use the API.",
            "**Iterate safely:** evolve designs in small, versioned increments so changes do not disrupt existing consumers."
          ],
          "canvasId": null,
          "sourcePath": "src/snippets/api-style-guide.json",
          "sourceUrl": null,
          "contentMarkdown": "{\r\n  \"guidelines\": [\r\n    {\r\n      \"id\": \"REST-CONTRACT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST implement endpoints, parameters, request bodies, response bodies, and error responses as defined in the validated OpenAPI contract.\",\r\n      \"relatedAuditItems\": [\r\n        \"spec-contains-schemas\",\r\n        \"schema-and-examples-pass\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CONTRACT-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST keep the implementation, published OpenAPI description, gateway configuration, and developer portal documentation aligned on every change.\",\r\n      \"relatedAuditItems\": [\r\n        \"docs-auto-generated\",\r\n        \"spec-auto-updated\",\r\n        \"spec-validated-on-change\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-VALIDATION-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST validate path parameters, query parameters, headers, and JSON request bodies against the OpenAPI schema before business processing.\",\r\n      \"relatedAuditItems\": [\r\n        \"mandatory-fields-specified\",\r\n        \"400-errors-specific\",\r\n        \"inputs-auto-validated\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DOMAIN-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST expose business-oriented resources and attributes rather than raw backend tables, internal service payloads, or system-specific field names.\",\r\n      \"relatedAuditItems\": [\r\n        \"hides-raw-backend-data\",\r\n        \"design-consistent\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DOMAIN-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST preserve validated meanings of entities, attributes, statuses, and source-of-truth rules across all endpoints and operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"design-consistent\",\r\n        \"general-data-uses-standard-values\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-NAMING-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST use descriptive English names for resources and attributes.\",\r\n      \"relatedAuditItems\": [\r\n        \"descriptive-english-naming\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-NAMING-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST avoid unexplained acronyms in public field and resource names.\",\r\n      \"relatedAuditItems\": [\r\n        \"field-names-avoid-acronyms\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DATA-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API MUST use ISO date-time values with timezone information where dates are exposed.\",\r\n      \"relatedAuditItems\": [\r\n        \"dates-use-iso\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-DATA-02\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"domain-modeling\",\r\n      \"requirement\": \"The REST API SHOULD use standard codes, controlled vocabularies, and standardized value sets where applicable.\",\r\n      \"relatedAuditItems\": [\r\n        \"general-data-uses-standard-values\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API MUST describe the business value and feature intent of each endpoint or capability.\",\r\n      \"relatedAuditItems\": [\r\n        \"endpoint-descriptions-present\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API MUST include examples for endpoints, request bodies, response bodies, and key attributes.\",\r\n      \"relatedAuditItems\": [\r\n        \"examples-present\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CX-03\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"consumer-experience\",\r\n      \"requirement\": \"The REST API SHOULD use consistent pagination, filtering, sorting, and response conventions across resources.\",\r\n      \"relatedAuditItems\": [\r\n        \"design-consistent\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-GET-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use GET for safe read-only operations and MUST NOT define a request body for GET operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-no-request-body\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-POST-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use POST for resource creation and other non-idempotent operations.\",\r\n      \"relatedAuditItems\": [\r\n        \"post-for-create-update\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-PUT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use PUT only for full resource replacement.\",\r\n      \"relatedAuditItems\": [\r\n        \"post-for-create-update\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-HTTP-DELETE-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"http-semantics\",\r\n      \"requirement\": \"The REST API MUST use DELETE to remove resources.\",\r\n      \"relatedAuditItems\": [\r\n        \"delete-for-remove\",\r\n        \"http-methods-match-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PATH-01\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"resource-modeling\",\r\n      \"requirement\": \"The REST API SHOULD keep endpoint paths shallow and avoid more than two resource or sub-resource levels unless explicitly justified.\",\r\n      \"relatedAuditItems\": [\r\n        \"paths-max-two-resources\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-200-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 200 OK for successful reads and updates that include a response body.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-no-request-body\",\r\n        \"post-returns-200\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-201-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 201 Created and the created resource identifier when a new resource is created.\",\r\n      \"relatedAuditItems\": [\r\n        \"create-returns-identifiers\",\r\n        \"post-returns-201\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-204-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API MUST return 204 No Content for successful delete operations that do not return a body.\",\r\n      \"relatedAuditItems\": [\r\n        \"delete-returns-204\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-RESP-204-02\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"status-codes\",\r\n      \"requirement\": \"The REST API SHOULD return 204 No Content for successful operations that intentionally return no response body.\",\r\n      \"relatedAuditItems\": [\r\n        \"get-empty-returns-204\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-400-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST define 400 Bad Request responses with specific and actionable validation error information.\",\r\n      \"relatedAuditItems\": [\r\n        \"400-errors-specific\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-401-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST return 401 Unauthorized for missing or invalid credentials.\",\r\n      \"relatedAuditItems\": [\r\n        \"401-unauthorized\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-ERROR-403-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"error-handling\",\r\n      \"requirement\": \"The REST API MUST return 403 Forbidden for authenticated clients lacking sufficient permission.\",\r\n      \"relatedAuditItems\": [\r\n        \"403-forbidden\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-VERSION-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"versioning\",\r\n      \"requirement\": \"The REST API MUST define a versioning strategy before production release, and the strategy MUST be supportable by the API gateway.\",\r\n      \"relatedAuditItems\": [\r\n        \"versioning-decided\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST require authentication for protected endpoints.\",\r\n      \"relatedAuditItems\": [\r\n        \"auth-protection\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST use token-based authentication or another approved modern authentication mechanism for protected endpoints.\",\r\n      \"relatedAuditItems\": [\r\n        \"token-auth\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-03\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST enforce object-level and function-level authorization on every protected operation.\",\r\n      \"relatedAuditItems\": [\r\n        \"401-unauthorized\",\r\n        \"403-forbidden\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-04\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST mitigate OWASP API risks including broken object level authorization, broken function level authorization, injection, and unrestricted resource consumption.\",\r\n      \"relatedAuditItems\": [\r\n        \"auth-protection\",\r\n        \"rate-limits-enforced\",\r\n        \"no-sensitive-data-in-urls\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-05\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST use HTTPS or another approved encrypted protocol for all traffic.\",\r\n      \"relatedAuditItems\": [\r\n        \"uses-https\",\r\n        \"encryption-in-transit\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-06\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST NOT expose sensitive information in URLs, query strings, logs, or unnecessary response fields.\",\r\n      \"relatedAuditItems\": [\r\n        \"no-sensitive-data-in-urls\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-07\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API SHOULD use UUIDs or other non-sequential public identifiers where direct database identifiers would increase exposure risk.\",\r\n      \"relatedAuditItems\": [\r\n        \"pseudo-identifiers\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-SEC-08\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"security\",\r\n      \"requirement\": \"The REST API MUST implement CSRF protection where relevant to the authentication model and client interaction pattern.\",\r\n      \"relatedAuditItems\": [\r\n        \"csrf-protection\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CAPACITY-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"resilience-capacity\",\r\n      \"requirement\": \"The REST API MUST define and enforce rate limits, throttling, or quotas according to capacity expectations.\",\r\n      \"relatedAuditItems\": [\r\n        \"rate-limits-enforced\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-CAPACITY-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"resilience-capacity\",\r\n      \"requirement\": \"The REST API MUST implement resilience controls such as timeouts, fallback behavior, and degradation handling according to business impact.\",\r\n      \"relatedAuditItems\": [\r\n        \"only-via-gateway\",\r\n        \"encryption-in-transit\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-OBS-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"observability\",\r\n      \"requirement\": \"The REST API MUST implement logs, metrics, and monitoring needed to observe validation failures, auth failures, traffic, latency, and dependency health.\",\r\n      \"relatedAuditItems\": [\r\n        \"rate-limits-enforced\",\r\n        \"message-integrity\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be published through an API management platform.\",\r\n      \"relatedAuditItems\": [\r\n        \"published-via-api-management\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be accessible only through approved API gateway paths and managed entry points.\",\r\n      \"relatedAuditItems\": [\r\n        \"only-via-gateway\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-03\",\r\n      \"priority\": \"SHOULD\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API SHOULD be visible in a developer portal with documentation generated from the contract.\",\r\n      \"relatedAuditItems\": [\r\n        \"visible-in-dev-portal\",\r\n        \"docs-auto-generated\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-PUBLISH-04\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"publishing-governance\",\r\n      \"requirement\": \"The REST API MUST be published under an approved organizational domain.\",\r\n      \"relatedAuditItems\": [\r\n        \"official-domain\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-AUDIT-01\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST validate the specification, schema, and examples on every change.\",\r\n      \"relatedAuditItems\": [\r\n        \"spec-validated-on-change\",\r\n        \"schema-and-examples-pass\"\r\n      ]\r\n    },\r\n    {\r\n      \"id\": \"REST-AUDIT-02\",\r\n      \"priority\": \"MUST\",\r\n      \"category\": \"contract-governance\",\r\n      \"requirement\": \"The REST API MUST pass concept, design, security, and production-readiness checks before release.\",\r\n      \"relatedAuditItems\": [\r\n        \"concept-items-audited\",\r\n        \"design-items-audited\"\r\n      ]\r\n    }\r\n  ]\r\n}",
          "draft": false
        },
        {
          "id": "api-community-engagement-strategies",
          "slug": "resources/api-community-engagement-strategies",
          "title": "API Community Engagement Strategies",
          "description": "A playbook for fostering API adoption by cultivating communities through content, support channels, feedback loops, and social engagement strategies.",
          "category": "guideline",
          "icon": "edit-document-outline",
          "order": 103,
          "outcomes": [
            "Shared understanding of the purpose and use of API Community Engagement Strategies",
            "A consistent approach to applying API Community Engagement Strategies",
            "Improved application of the related practices"
          ],
          "steps": [
            "Develop marketing strategies to promote APIs to target audiences, including social media, blogs, and webinars.",
            "Create promotional materials (e.g., case studies, success stories) that highlight the value and benefits of APIs.",
            "Create educational materials (e.g., tutorials, documentation) that explain API features, benefits, and usage patterns.",
            "Engage with API consumers through feedback loops, support channels, and community forums to understand their needs and improve API adoption.",
            "Analyze API usage metrics and incorporate user feedback into API iterations."
          ],
          "canvasId": null,
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": true
        },
        {
          "id": "api-compliance-best-practices",
          "slug": "resources/api-compliance-best-practices",
          "title": "API Compliance Best Practices",
          "description": "Ensure APIs meet legal, regulatory, and internal compliance through documentation, controls, and automated validations.",
          "category": "guideline",
          "icon": "edit-document-outline",
          "order": 104,
          "outcomes": [
            "Shared understanding of the purpose and use of API Compliance Best Practices",
            "A consistent approach to applying API Compliance Best Practices",
            "Improved application of the related practices"
          ],
          "steps": [
            "Document compliance measures and ensure they are communicated to stakeholders and consumers.",
            "Implement measures to ensure APIs comply with these requirements, including data encryption, access controls, and audit trails.",
            "Use checklists, linters, and testing tools to verify consistency and conformance with standards."
          ],
          "canvasId": null,
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": true
        },
        {
          "id": "api-development-best-practices",
          "slug": "resources/api-development-best-practices",
          "title": "API Development Best Practices",
          "description": "Implementation guidance for turning a validated API interface contract into a consistent, maintainable API codebase using standard libraries, reusable patterns, and aligned development workflows.",
          "category": "guideline",
          "icon": "edit-document-outline",
          "order": 112,
          "outcomes": [
            "Shared understanding of the purpose and use of API Development Best Practices",
            "A consistent approach to applying API Development Best Practices",
            "Improved application of the related practices"
          ],
          "steps": [
            "Apply these practices to the validated API interface contract and implementation plan before coding begins.",
            "Use established frameworks, libraries, and coding standards to implement the contract consistently and maintainably."
          ],
          "canvasId": null,
          "sourcePath": "src/snippets/api-design-principles-guidance.md",
          "sourceUrl": null,
          "contentMarkdown": "## How to start the API Delivery work based on the previous phases (\"stations\")\r\n\r\nUse this guidance at the start of `API Delivery` after the API contract (e.g. OpenAPI) and the key outputs from earlier stations have been reviewed and accepted.\r\n\r\nThe goal is not to invent implementation in isolation. The goal is to turn the agreed outputs from earlier stations into concrete code structure, validation rules, runtime behavior, and API product delivery decisions.\r\n\r\n---\r\n\r\n### 1. Start From The Validated Contract\r\n\r\n- Treat the validated API contract as the main reference point for implementation decisions.\r\n- Keep the contract and implementation aligned throughout the API product delivery.\r\n- Use the contract to drive request validation, response mapping, documentation, and tests.\r\n\r\n---\r\n\r\n### 2. Use Domain Outputs To Preserve Business Meaning\r\n\r\n- Use the `Domain Canvas` outputs to guide naming, how the implementation is split into clear business responsibilities, and how different backend systems are connected without exposing their differences.\r\n- Preserve the validated meanings of entities, attributes, statuses, and source-of-truth rules.\r\n- Avoid leaking backend-specific models or inconsistencies into the public API.\r\n\r\n---\r\n\r\n### 3. Use Journey Outputs To Preserve Critical Flows\r\n\r\n- Use the `Customer Journey Canvas` outputs to identify which user flows are most important to support first.\r\n- Use the `API Consumer Experience` outputs to keep the API understandable, predictable, and easy to integrate.\r\n- Let the agreed journey priorities decide which implementation paths need the highest reliability, lowest latency, clearest errors, and strongest operational focus.\r\n\r\n---\r\n\r\n### 4. Use Value Proposition Outputs To Preserve Consumer Value\r\n\r\n- Use the `API Value Proposition Canvas` outputs to keep the implementation focused on the agreed pains, gains, and API features.\r\n- Preserve the field meanings, behavior, and promises that made the API valuable in the earlier stations.\r\n- Ensure error handling, freshness, and naming support both the intended developer experience and the business use case.\r\n\r\n---\r\n\r\n### 5. Use Architecture Outputs To Shape Runtime Decisions\r\n\r\n- Use the `Business Impact Canvas` outputs to guide resilience, timeout, fallback, and degradation decisions.\r\n- Use the `Locations Canvas` outputs to guide network boundaries, trust boundaries, access paths, and deployment constraints.\r\n- Use the `Capacity Canvas` outputs to guide rate limits, caching, scaling, and peak-load behavior.\r\n- Use the `API Metrics And Analytics` guidance to decide what must be observed from the first implementation onward.\r\n\r\n---\r\n\r\n### 6. Use Interaction And Protocol Design Outputs To Shape Code Structure\r\n\r\n- Use the `Interaction Canvas` outputs to avoid implementing unsupported interaction styles too early.\r\n- Use the `REST`, `Event`, or `GraphQL` design outputs to shape protocol-specific request, response, and validation behavior.\r\n- Reflect the selected interaction style clearly in code structure, responsibilities, and testing strategy.\r\n\r\n---\r\n\r\n### 7. Use Audit Outputs To Improve Delivery Before Coding Goes Too Far\r\n\r\n- Use the audit findings to remove ambiguity before implementation spreads across the codebase.\r\n- Fix unclear request rules, missing validation, weak error contracts, and operational gaps early.\r\n- Treat audit as a design-improvement loop before production, not only as a final decision gate.\r\n\r\n---\r\n\r\n### 8. Apply The Guidance, Then Summarize\r\n\r\n- Apply this guidance to the current API and implementation plan.\r\n- Summarize the implications for code structure, request validation, source integration, security, monitoring and alerts, and testing.\r\n- Do not create a separate delivery artifact unless the team or user specifically needs one.\r\n",
          "draft": true
        },
        {
          "id": "api-metrics-and-analytics",
          "slug": "resources/api-metrics-and-analytics",
          "title": "API Metrics And Analytics",
          "description": "A resource for defining, collecting, and analyzing API performance and usage data to align technical KPIs with business outcomes.",
          "category": "guideline",
          "icon": "edit-document-outline",
          "order": 119,
          "outcomes": [
            "Shared understanding of the purpose and use of API Metrics And Analytics",
            "A consistent approach to applying API Metrics And Analytics",
            "Improved application of the related practices"
          ],
          "steps": [
            "Identify key performance indicators (KPIs) to measure API success against business goals.",
            "Define and monitor performance metrics (e.g., API calls, latency, error rates) and adoption metrics (e.g., NPS).",
            "Monitor API initiatives to ensure adherence to operating guidelines and governance practices"
          ],
          "canvasId": null,
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": true
        },
        {
          "id": "api-onboarding-best-practices",
          "slug": "resources/api-onboarding-best-practices",
          "title": "API Onboarding Best Practices",
          "description": "Best practices to streamline API consumer onboarding journeys with step-by-step registration, discovery, and first-call guidance.",
          "category": "guideline",
          "icon": "edit-document-outline",
          "order": 121,
          "outcomes": [
            "Shared understanding of the purpose and use of API Onboarding Best Practices",
            "A consistent approach to applying API Onboarding Best Practices",
            "Improved application of the related practices"
          ],
          "steps": [
            "Define the API consumer journey from discovery to troubleshooting, identifying key touchpoints and pain points.",
            "Develop onboarding processes and resources to help API consumers understand how to use APIs effectively.",
            "Document how consumers find and use the API, including onboarding processes and registration."
          ],
          "canvasId": null,
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": true
        },
        {
          "id": "api-portfolio-management-guidelines",
          "slug": "resources/api-portfolio-management-guidelines",
          "title": "API Portfolio Management Guidelines",
          "description": "A guide to strategically manage an organization's API suite—prioritizing APIs, allocating resources, and monitoring performance across lifecycles.",
          "category": "guideline",
          "icon": "edit-document-outline",
          "order": 123,
          "outcomes": [
            "Shared understanding of the purpose and use of API Portfolio Management Guidelines",
            "A consistent approach to applying API Portfolio Management Guidelines",
            "Improved application of the related practices"
          ],
          "steps": [
            "Define portfolio management practices that outline the processes for managing the API portfolio, including prioritization, monitoring, and optimization.",
            "Define budget and resource management practices that outline the processes for managing budgets and resources for API initiatives.",
            "Establish criteria for evaluating and prioritizing budget allocations based on business value, impact, and alignment with strategic initiatives.",
            "Monitor the API portfolio to ensure APIs are delivering value, meeting performance expectations, and aligning with business goals."
          ],
          "canvasId": null,
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": true
        },
        {
          "id": "api-security-best-practices",
          "slug": "resources/api-security-best-practices",
          "title": "API Security Best Practices",
          "description": "A set of actionable controls for securing APIs, including authentication, authorization, encryption, rate-limiting, and pipeline-level compliance checks.",
          "category": "guideline",
          "icon": "edit-document-outline",
          "order": 130,
          "outcomes": [
            "Shared understanding of the purpose and use of API Security Best Practices",
            "A consistent approach to applying API Security Best Practices",
            "Improved application of the related practices"
          ],
          "steps": [
            "Ensure APIs meet security and compliance requirements through automated checks and audits.",
            "Implement security measures such as authentication, authorization, encryption, and rate limiting to protect APIs from threats.",
            "Implement automated security checks and compliance validations in the CI/CD pipeline to ensure APIs are secure and compliant."
          ],
          "canvasId": null,
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": true
        },
        {
          "id": "api-team-structure-guidelines",
          "slug": "resources/api-team-structure-guidelines",
          "title": "API Team Structure Guidelines",
          "description": "Organizational guidance for defining roles and responsibilities within API teams to ensure clarity, collaboration, and accountability.",
          "category": "guideline",
          "icon": "edit-document-outline",
          "order": 132,
          "outcomes": [
            "Shared understanding of the purpose and use of API Team Structure Guidelines",
            "A consistent approach to applying API Team Structure Guidelines",
            "Improved application of the related practices"
          ],
          "steps": [
            "Define team structures and roles for API teams, including API product owners, developers, architects, and operations."
          ],
          "canvasId": null,
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": true
        },
        {
          "id": "api-testing-best-practices",
          "slug": "resources/api-testing-best-practices",
          "title": "API Testing Best Practices",
          "description": "Guidelines for implementing automated functional, performance, and security testing throughout the API lifecycle.",
          "category": "guideline",
          "icon": "edit-document-outline",
          "order": 133,
          "outcomes": [
            "Shared understanding of the purpose and use of API Testing Best Practices",
            "A consistent approach to applying API Testing Best Practices",
            "Improved application of the related practices"
          ],
          "steps": [
            "Test APIs for functionality, security, and performance using automated testing tools.",
            "Integrate functional and non-functional testing into the CI/CD pipeline to ensure APIs meet quality standards.",
            "Use automated testing tools to validate API functionality, security, and performance."
          ],
          "canvasId": null,
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": true
        },
        {
          "id": "api-training-programs",
          "slug": "resources/api-training-programs",
          "title": "API Training Programs",
          "description": "A roadmap for upskilling teams with structured learning paths in API design, governance, performance, and security.",
          "category": "guideline",
          "icon": "edit-document-outline",
          "order": 134,
          "outcomes": [
            "Shared understanding of the purpose and use of API Training Programs",
            "A consistent approach to applying API Training Programs",
            "Improved application of the related practices"
          ],
          "steps": [
            "Identify key API skills and knowledge areas that need enhancement, such as API design, security, and performance.",
            "Encourage continuous learning through online courses, certifications, and community engagement.",
            "Provide training and resources to help teams adopt an API-first mindset and understand the benefits of APIs.",
            "Provide training programs, workshops, and resources to help teams enhance their API skills and knowledge."
          ],
          "canvasId": null,
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": true
        },
        {
          "id": "api-versioning-best-practices",
          "slug": "resources/api-versioning-best-practices",
          "title": "API Versioning Best Practices",
          "description": "Strategies for introducing, maintaining, and retiring API versions while preserving backward compatibility and consumer trust.",
          "category": "guideline",
          "icon": "edit-document-outline",
          "order": 138,
          "outcomes": [
            "Shared understanding of the purpose and use of API Versioning Best Practices",
            "A consistent approach to applying API Versioning Best Practices",
            "Improved application of the related practices"
          ],
          "steps": [
            "Define versioning strategies for APIs to manage changes and ensure backward compatibility."
          ],
          "canvasId": null,
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": true
        },
        {
          "id": "apiops-CI-CD-for-apis",
          "slug": "resources/apiops-CI-CD-for-apis",
          "title": "APIOps CI/CD For APIs",
          "description": "Deployment guidance that integrates API lifecycle tasks—design, testing, governance—into continuous integration and delivery pipelines.",
          "category": "guideline",
          "icon": "edit-document-outline",
          "order": 140,
          "outcomes": [
            "Shared understanding of the purpose and use of APIOps CI/CD For APIs",
            "A consistent approach to applying APIOps CI/CD For APIs",
            "Improved application of the related practices"
          ],
          "steps": [
            "Use CI/CD pipelines to automate build, test, and deployment processes, ensuring consistent quality and traceability.",
            "Integrate automated tests into the CI/CD pipeline to ensure continuous validation of API quality.",
            "Implement deployment strategies (e.g., blue-green deployments, canary releases) to minimize risks during API releases.",
            "Establish a habit of reviewing metrics and planning continuous improvement activities."
          ],
          "canvasId": null,
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": true
        },
        {
          "id": "competitor-analysis-template",
          "slug": "resources/competitor-analysis-template",
          "title": "Competitor Analysis Template",
          "description": "A structured worksheet to benchmark your API offerings against competitors by mapping strengths, weaknesses, and value differentiators.",
          "category": "guideline",
          "icon": "edit-document-outline",
          "order": 143,
          "outcomes": [
            "Shared understanding of the purpose and use of Competitor Analysis Template",
            "A consistent approach to applying Competitor Analysis Template",
            "Improved application of the related practices"
          ],
          "steps": [
            "Conduct a competitive analysis to identify key competitors, and their API offerings.",
            "Analyze competitor APIs to understand their strengths, weaknesses, and unique selling points."
          ],
          "canvasId": null,
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": true
        },
        {
          "id": "contract-first-design",
          "slug": "resources/contract-first-design",
          "title": "Contract First Design",
          "description": "A guideline advocating for API-first approaches using formal contracts (e.g., OpenAPI) to align stakeholders before development.",
          "category": "guideline",
          "icon": "edit-document-outline",
          "order": 146,
          "outcomes": [
            "Shared understanding of the purpose and use of Contract First Design",
            "A consistent approach to applying Contract First Design",
            "Improved application of the related practices"
          ],
          "steps": [
            "Apply contract-first or design-first approaches to ensure API interface contracts are validated before implementation.",
            "Define API interface contracts that outline the expectations, responsibilities, and usage guidelines for each API.",
            "Use standardized formats (e.g., OpenAPI, AsyncAPI) to create machine-readable API interface contracts that are easy to share and validate."
          ],
          "canvasId": null,
          "sourcePath": "src/snippets/api-contract-example.yaml",
          "sourceUrl": null,
          "contentMarkdown": "openapi: 3.0.3\r\ninfo:\r\n  title: Sample Catalog API\r\n  version: 1.0.0\r\n  description: |\r\n    Starter example for a read-only APIOps Cycles API.\r\n    This example keeps the contract audit-friendly and easy to extend.\r\nservers:\r\n  - url: /v1\r\n    description: Versioned API base path\r\ntags:\r\n  - name: catalog\r\n    description: Browse and search catalog items\r\npaths:\r\n  /items:\r\n    get:\r\n      tags: [catalog]\r\n      summary: List catalog items\r\n      description: Returns a paginated list of public catalog items.\r\n      operationId: listItems\r\n      parameters:\r\n        - $ref: \"#/components/parameters/searchTerm\"\r\n        - $ref: \"#/components/parameters/categoryId\"\r\n        - $ref: \"#/components/parameters/page\"\r\n        - $ref: \"#/components/parameters/pageSize\"\r\n      responses:\r\n        \"200\":\r\n          description: Item list\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemListResponse\"\r\n              examples:\r\n                default:\r\n                  value:\r\n                    data:\r\n                      - itemId: item-123\r\n                        slug: blue-widget\r\n                        name: Blue Widget\r\n                        status: published\r\n                    page:\r\n                      number: 1\r\n                      size: 20\r\n                      totalItems: 1\r\n        \"400\":\r\n          $ref: \"#/components/responses/BadRequest\"\r\n        \"429\":\r\n          $ref: \"#/components/responses/TooManyRequests\"\r\n  /items/{itemId}:\r\n    get:\r\n      tags: [catalog]\r\n      summary: Get item by id\r\n      description: Returns a single public catalog item by opaque identifier.\r\n      operationId: getItemById\r\n      parameters:\r\n        - $ref: \"#/components/parameters/itemId\"\r\n      responses:\r\n        \"200\":\r\n          description: Item details\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemDetail\"\r\n        \"400\":\r\n          $ref: \"#/components/responses/BadRequest\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\n  /items/by-slug/{slug}:\r\n    get:\r\n      tags: [catalog]\r\n      summary: Get item by slug\r\n      description: Returns a single item by public slug.\r\n      operationId: getItemBySlug\r\n      parameters:\r\n        - $ref: \"#/components/parameters/slug\"\r\n      responses:\r\n        \"200\":\r\n          description: Item details\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemDetail\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\n  /categories/{categoryId}/items:\r\n    get:\r\n      tags: [catalog]\r\n      summary: List items in category\r\n      description: Returns public items in a category.\r\n      operationId: listItemsByCategory\r\n      parameters:\r\n        - $ref: \"#/components/parameters/categoryId\"\r\n      responses:\r\n        \"200\":\r\n          description: Category item list\r\n          content:\r\n            application/json:\r\n              schema:\r\n                $ref: \"#/components/schemas/ItemListResponse\"\r\n        \"404\":\r\n          $ref: \"#/components/responses/NotFound\"\r\ncomponents:\r\n  parameters:\r\n    itemId:\r\n      name: itemId\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9][a-z0-9-]{1,63}$\"\r\n      example: item-123\r\n    slug:\r\n      name: slug\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9]+(?:-[a-z0-9]+)*$\"\r\n      example: blue-widget\r\n    categoryId:\r\n      name: categoryId\r\n      in: path\r\n      required: true\r\n      schema:\r\n        type: string\r\n        pattern: \"^[a-z0-9][a-z0-9-]{1,63}$\"\r\n      example: home-goods\r\n    searchTerm:\r\n      name: searchTerm\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: string\r\n        minLength: 1\r\n      example: widget\r\n    page:\r\n      name: page\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: integer\r\n        minimum: 1\r\n        default: 1\r\n    pageSize:\r\n      name: pageSize\r\n      in: query\r\n      required: false\r\n      schema:\r\n        type: integer\r\n        minimum: 1\r\n        maximum: 100\r\n        default: 20\r\n  responses:\r\n    BadRequest:\r\n      description: Validation failed\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n          examples:\r\n            default:\r\n              value:\r\n                code: BAD_REQUEST\r\n                message: Invalid request\r\n    NotFound:\r\n      description: Resource not found\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n    TooManyRequests:\r\n      description: Rate limit exceeded\r\n      headers:\r\n        Retry-After:\r\n          schema:\r\n            type: integer\r\n          description: Seconds until the next allowed request.\r\n      content:\r\n        application/json:\r\n          schema:\r\n            $ref: \"#/components/schemas/ErrorResponse\"\r\n  schemas:\r\n    ItemListResponse:\r\n      type: object\r\n      required: [data, page]\r\n      properties:\r\n        data:\r\n          type: array\r\n          items:\r\n            $ref: \"#/components/schemas/ItemSummary\"\r\n        page:\r\n          $ref: \"#/components/schemas/Page\"\r\n    ItemSummary:\r\n      type: object\r\n      required: [itemId, slug, name, status]\r\n      properties:\r\n        itemId:\r\n          type: string\r\n        slug:\r\n          type: string\r\n        name:\r\n          type: string\r\n        status:\r\n          type: string\r\n          enum: [published, hidden]\r\n    ItemDetail:\r\n      allOf:\r\n        - $ref: \"#/components/schemas/ItemSummary\"\r\n        - type: object\r\n          properties:\r\n            description:\r\n              type: string\r\n            categories:\r\n              type: array\r\n              items:\r\n                type: string\r\n            variants:\r\n              type: array\r\n              items:\r\n                $ref: \"#/components/schemas/Variant\"\r\n    Variant:\r\n      type: object\r\n      required: [variantId, sku, price, inventory]\r\n      properties:\r\n        variantId:\r\n          type: string\r\n        sku:\r\n          type: string\r\n        price:\r\n          $ref: \"#/components/schemas/Price\"\r\n        inventory:\r\n          $ref: \"#/components/schemas/Inventory\"\r\n    Price:\r\n      type: object\r\n      required: [amount, currency]\r\n      properties:\r\n        amount:\r\n          type: number\r\n          format: decimal\r\n        currency:\r\n          type: string\r\n          example: EUR\r\n    Inventory:\r\n      type: object\r\n      required: [available]\r\n      properties:\r\n        available:\r\n          type: integer\r\n          minimum: 0\r\n        reserved:\r\n          type: integer\r\n          minimum: 0\r\n        source:\r\n          type: string\r\n    Page:\r\n      type: object\r\n      required: [number, size, totalItems]\r\n      properties:\r\n        number:\r\n          type: integer\r\n        size:\r\n          type: integer\r\n        totalItems:\r\n          type: integer\r\n    ErrorResponse:\r\n      type: object\r\n      required: [code, message]\r\n      properties:\r\n        code:\r\n          type: string\r\n        message:\r\n          type: string\r\n",
          "draft": true
        },
        {
          "id": "cross-functional-collaboration-best-practices",
          "slug": "resources/cross-functional-collaboration-best-practices",
          "title": "Cross Functional Collaboration Best Practices",
          "description": "Practices to facilitate communication and alignment between business and tech teams when planning or delivering APIs.",
          "category": "guideline",
          "icon": "edit-document-outline",
          "order": 147,
          "outcomes": [
            "Shared understanding of the purpose and use of Cross Functional Collaboration Best Practices",
            "A consistent approach to applying Cross Functional Collaboration Best Practices",
            "Improved application of the related practices"
          ],
          "steps": [
            "Encourage cross-functional collaboration between API teams, business units, and stakeholders to align API initiatives with business goals."
          ],
          "canvasId": null,
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": true
        },
        {
          "id": "data-privacy-guidelines",
          "slug": "resources/data-privacy-guidelines",
          "title": "Data Privacy Guidelines",
          "description": "Design considerations to ensure APIs meet data protection regulations like GDPR through anonymization and access controls.",
          "category": "guideline",
          "icon": "edit-document-outline",
          "order": 148,
          "outcomes": [
            "Shared understanding of the purpose and use of Data Privacy Guidelines",
            "A consistent approach to applying Data Privacy Guidelines",
            "Improved application of the related practices"
          ],
          "steps": [
            "Ensure user data privacy by implementing data protection measures, such as anonymization and access controls."
          ],
          "canvasId": null,
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": true
        },
        {
          "id": "domainCanvas",
          "slug": "resources/domain-canvas",
          "title": "Domain Canvas",
          "description": "A modeling tool to define and communicate the key entities and relationships in your domain, ensuring semantic consistency across capabilities, integrations, APIs, data products, and services.",
          "category": "canvas",
          "icon": "dashboard-outline",
          "order": 152,
          "outcomes": [
            "Shared domain model and terminology",
            "Core entities, relationships, rules, and ownership clarified",
            "Semantic consistency across capabilities, integrations, APIs, data products, and services"
          ],
          "steps": [
            "Define core entities, their attributes, and relationships to create a shared conceptual understanding across capabilities, integrations, APIs, data products, and services."
          ],
          "canvasId": "domainCanvas",
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": false
        },
        {
          "id": "ecosystem-vision-template",
          "slug": "resources/ecosystem-vision-template",
          "title": "Ecosystem Vision Template",
          "description": "A strategic planning tool to define the API ecosystem, including target partners, value chains, and integration opportunities.",
          "category": "guideline",
          "icon": "edit-document-outline",
          "order": 154,
          "outcomes": [
            "Shared understanding of the purpose and use of Ecosystem Vision Template",
            "A consistent approach to applying Ecosystem Vision Template",
            "Improved application of the related practices"
          ],
          "steps": [
            "Conduct market research to identify trends, opportunities, and threats in the API landscape.",
            "Identify key ecosystem partners and stakeholders who will benefit from or contribute to the ecosystem.",
            "Identify gaps in the market that your APIs can fill, based on competitor offerings.",
            "Identify potential partners whose APIs can enhance your API capabilities and value proposition.",
            "Develop a differentiation strategy that highlights unique features and benefits of your APIs.",
            "Define the ecosystem vision for your APIs, including how they will interact with other systems and platforms.",
            "Design APIs to enable seamless integration and collaboration within the ecosystem."
          ],
          "canvasId": null,
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": true
        },
        {
          "id": "industry-standards-and-best-practices",
          "slug": "resources/industry-standards-and-best-practices",
          "title": "Industry Standards And Best Practices",
          "description": "A reference resource for aligning API design and operation with widely recognized industry frameworks and specifications.",
          "category": "guideline",
          "icon": "edit-document-outline",
          "order": 157,
          "outcomes": [
            "Shared understanding of the purpose and use of Industry Standards And Best Practices",
            "A consistent approach to applying Industry Standards And Best Practices",
            "Improved application of the related practices"
          ],
          "steps": [
            "Identify industry standards and best practices to ensure APIs are competitive and compliant."
          ],
          "canvasId": null,
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": true
        },
        {
          "id": "partner-integration-guidelines",
          "slug": "resources/partner-integration-guidelines",
          "title": "Partner Integration Guidelines",
          "description": "Integration checklists and communication patterns to manage technical and legal aspects of third-party API relationships.",
          "category": "guideline",
          "icon": "edit-document-outline",
          "order": 164,
          "outcomes": [
            "Shared understanding of the purpose and use of Partner Integration Guidelines",
            "A consistent approach to applying Partner Integration Guidelines",
            "Improved application of the related practices"
          ],
          "steps": [
            "Establish integration processes and guidelines for collaborating with partners, including technical integration, data sharing, and support.",
            "Monitor partner API performance and compliance to ensure reliability and alignment with your API strategy."
          ],
          "canvasId": null,
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": true
        },
        {
          "id": "role-communication-best-practices",
          "slug": "resources/role-communication-best-practices",
          "title": "Role Communication Best Practices",
          "description": "Tools to define and document who is responsible for what within API initiatives, ensuring handoffs and accountability are clear.",
          "category": "guideline",
          "icon": "edit-document-outline",
          "order": 167,
          "outcomes": [
            "Shared understanding of the purpose and use of Role Communication Best Practices",
            "A consistent approach to applying Role Communication Best Practices",
            "Improved application of the related practices"
          ],
          "steps": [
            "Establish clear responsibilities for each role, including API design, development, testing, and operations.",
            "Ensure roles and responsibilities are communicated to all team members and stakeholders to ensure alignment."
          ],
          "canvasId": null,
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": true
        },
        {
          "id": "scalable-infrastructure-best-practices",
          "slug": "resources/scalable-infrastructure-best-practices",
          "title": "Scalable Infrastructure Best Practices",
          "description": "Architectural guidance to ensure APIs are deployed on infrastructure that can elastically handle usage spikes and growth.",
          "category": "guideline",
          "icon": "edit-document-outline",
          "order": 168,
          "outcomes": [
            "Shared understanding of the purpose and use of Scalable Infrastructure Best Practices",
            "A consistent approach to applying Scalable Infrastructure Best Practices",
            "Improved application of the related practices"
          ],
          "steps": [
            "Design API infrastructure to be scalable and resilient, using cloud-native patterns and technologies.",
            "Monitor infrastructure performance and capacity to ensure it can handle growing demand."
          ],
          "canvasId": null,
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": true
        },
        {
          "id": "service-agreement-template",
          "slug": "resources/service-agreement-template",
          "title": "Service Agreement Template",
          "description": "A customizable agreement format that defines expectations, SLAs, responsibilities, and access terms for API consumption.",
          "category": "guideline",
          "icon": "edit-document-outline",
          "order": 172,
          "outcomes": [
            "Shared understanding of the purpose and use of Service Agreement Template",
            "A consistent approach to applying Service Agreement Template",
            "Improved application of the related practices"
          ],
          "steps": [
            "Define service agreements that outline the expectations, service levels, and responsibilities for each API.",
            "Use standardized formats to create machine-readable service agreements that are easy to share and validate.",
            "Ensure service agreements are reviewed and approved by stakeholders to ensure alignment and clarity."
          ],
          "canvasId": null,
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": true
        },
        {
          "id": "stakeholder-engagement-best-practices",
          "slug": "resources/stakeholder-engagement-best-practices",
          "title": "Stakeholder Engagement Best Practices",
          "description": "Engagement tactics for aligning internal and external stakeholders around shared API goals, value, and governance.",
          "category": "guideline",
          "icon": "edit-document-outline",
          "order": 173,
          "outcomes": [
            "Shared understanding of the purpose and use of Stakeholder Engagement Best Practices",
            "A consistent approach to applying Stakeholder Engagement Best Practices",
            "Improved application of the related practices"
          ],
          "steps": [
            "Engage stakeholders to ensure alignment and support for API initiatives."
          ],
          "canvasId": null,
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": true
        },
        {
          "id": "test-automation-frameworks",
          "slug": "resources/test-automation-frameworks",
          "title": "Test Automation Frameworks",
          "description": "Recommended tools and patterns for automating API interface contract, regression, and integration testing across environments.",
          "category": "guideline",
          "icon": "edit-document-outline",
          "order": 174,
          "outcomes": [
            "Shared understanding of the purpose and use of Test Automation Frameworks",
            "A consistent approach to applying Test Automation Frameworks",
            "Improved application of the related practices"
          ],
          "steps": [
            "Implement test automation frameworks that support contract testing, integration testing, and end-to-end testing."
          ],
          "canvasId": null,
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": true
        },
        {
          "id": "vendor-management-best-practices",
          "slug": "resources/vendor-management-best-practices",
          "title": "Vendor Management Best Practices",
          "description": "Framework for evaluating and managing external API vendors and third-party integrations based on risk, performance, and compliance.",
          "category": "guideline",
          "icon": "edit-document-outline",
          "order": 178,
          "outcomes": [
            "Shared understanding of the purpose and use of Vendor Management Best Practices",
            "A consistent approach to applying Vendor Management Best Practices",
            "Improved application of the related practices"
          ],
          "steps": [
            "Establish vendor management processes to evaluate, onboard, and monitor third-party API vendors.",
            "Define criteria for evaluating vendor APIs, including reliability, security, and compliance."
          ],
          "canvasId": null,
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": true
        },
        {
          "id": "integration-style-selection-guide",
          "slug": "resources/integration-style-selection-guide",
          "title": "Integration Style Selection Guide",
          "description": "Guidance for choosing between API, event, file, stream, data product, direct integration, or hybrid implementation styles based on requirements and constraints.",
          "category": "guideline",
          "icon": "edit-document-outline",
          "order": 180,
          "outcomes": [
            "Justified integration implementation style",
            "Tradeoffs documented across integration style options",
            "Selected style traceable to consumer, platform, data, and operational requirements"
          ],
          "steps": [
            "Compare viable integration styles against latency, volume, coupling, data ownership, freshness, governance, and operability needs.",
            "Identify when API, event, file, stream, data product, direct integration, or hybrid approaches fit the use case.",
            "Document constraints, risks, and platform dependencies for the selected implementation style.",
            "Record why rejected alternatives were not selected."
          ],
          "canvasId": null,
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": true
        },
        {
          "id": "process-workflow-design-guide",
          "slug": "resources/process-workflow-design-guide",
          "title": "Process Workflow Design Guide",
          "description": "Guidance for modeling the process steps, roles, handoffs, decision points, states, inputs, outputs, and exceptions that shape an automation workflow.",
          "category": "guideline",
          "icon": "edit-document-outline",
          "order": 181,
          "outcomes": [
            "Clear automation workflow design",
            "Process steps and handoffs documented before implementation",
            "Workflow states, inputs, outputs, and exception paths understood"
          ],
          "steps": [
            "Map the current and target process flow, including human and system responsibilities.",
            "Identify workflow triggers, states, decisions, data inputs, outputs, and completion criteria.",
            "Document handoffs between users, systems, operations, and support roles.",
            "Confirm which steps should be automated and which require human judgment."
          ],
          "canvasId": null,
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": true
        },
        {
          "id": "decision-business-rules-guide",
          "slug": "resources/decision-business-rules-guide",
          "title": "Decision And Business Rules Guide",
          "description": "Guidance for capturing rules, thresholds, decisions, approvals, eligibility checks, and rule ownership for automation design.",
          "category": "guideline",
          "icon": "edit-document-outline",
          "order": 182,
          "outcomes": [
            "Explicit decisions and business rules",
            "Rules and thresholds documented with owners",
            "Automation decisions traceable to policy, process, or business intent"
          ],
          "steps": [
            "List decisions the automation must make or support.",
            "Document rule conditions, thresholds, exceptions, approvals, and escalation points.",
            "Identify rule owners and change governance for each decision area."
          ],
          "canvasId": null,
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": true
        },
        {
          "id": "automation-trigger-handoff-exception-guide",
          "slug": "resources/automation-trigger-handoff-exception-guide",
          "title": "Automation Trigger, Handoff And Exception Guide",
          "description": "Guidance for defining automation triggers, human handoffs, exception handling, retries, compensating actions, and support escalation paths.",
          "category": "guideline",
          "icon": "edit-document-outline",
          "order": 183,
          "outcomes": [
            "Defined automation triggers and exception paths",
            "Human handoffs and support escalations are explicit",
            "Exceptions, retries, and compensating actions are designed before delivery"
          ],
          "steps": [
            "Define the events, schedules, user actions, or system states that trigger the automation.",
            "Map handoffs from automation to users, operators, or support teams.",
            "Document exceptions, retry rules, timeout behavior, and fallback paths.",
            "Define alerts and escalation thresholds for failed or ambiguous automation outcomes."
          ],
          "canvasId": null,
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": true
        },
        {
          "id": "automation-testing-guide",
          "slug": "resources/automation-testing-guide",
          "title": "Automation Testing Guide",
          "description": "Guidance for testing automated workflows, decisions, integrations, exceptions, rollback behavior, supervision, and user impact before release.",
          "category": "guideline",
          "icon": "edit-document-outline",
          "order": 184,
          "outcomes": [
            "Validated automation behavior",
            "Workflow, rule, exception, and integration tests defined",
            "Release confidence for automated and human-assisted paths"
          ],
          "steps": [
            "Create tests for happy paths, edge cases, exceptions, retries, and handoffs.",
            "Validate business rules and decision outcomes with representative data.",
            "Test rollback, recovery, observability, and manual intervention paths.",
            "Include users and operators in acceptance testing where the automation changes work practices."
          ],
          "canvasId": null,
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": true
        },
        {
          "id": "automation-operational-ownership-guide",
          "slug": "resources/automation-operational-ownership-guide",
          "title": "Automation Operational Ownership Guide",
          "description": "Guidance for defining ownership, runbooks, supervision, support, monitoring, change control, and continuous improvement responsibilities for automations.",
          "category": "guideline",
          "icon": "edit-document-outline",
          "order": 185,
          "outcomes": [
            "Clear automation operating model",
            "Ownership, support, and escalation responsibilities assigned",
            "Monitoring and change practices ready for live operation"
          ],
          "steps": [
            "Define business, technical, and operational owners for the automation.",
            "Document runbooks, support paths, monitoring signals, service expectations, and escalation rules.",
            "Set change control and review practices for workflow, platform, and rule updates."
          ],
          "canvasId": null,
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": true
        },
        {
          "id": "automation-rollback-supervision-guide",
          "slug": "resources/automation-rollback-supervision-guide",
          "title": "Automation Rollback And Supervision Guide",
          "description": "Guidance for designing rollback, pause, manual override, monitoring, supervision, and recovery paths for automations.",
          "category": "guideline",
          "icon": "edit-document-outline",
          "order": 186,
          "outcomes": [
            "Controlled automation recovery paths",
            "Rollback, pause, and override behavior documented",
            "Supervision needs and recovery responsibilities defined"
          ],
          "steps": [
            "Identify actions that must be reversible, paused, or manually overridden.",
            "Define rollback, compensation, and recovery procedures for failed or incorrect automation outcomes.",
            "Document supervision thresholds, alerts, and manual decision points.",
            "Validate recovery procedures before release."
          ],
          "canvasId": null,
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": true
        },
        {
          "id": "automation-readiness-checklist",
          "slug": "resources/automation-readiness-checklist",
          "title": "Automation Readiness Checklist",
          "description": "A checklist for validating automation workflow, controls, risk, compliance, human oversight, testing evidence, rollback, operations, and release readiness.",
          "category": "checklist",
          "icon": "check-box-outline",
          "order": 187,
          "outcomes": [
            "Documented automation readiness",
            "Known readiness gaps and mitigations before release",
            "Evidence for quality, risk, compliance, oversight, and operational approval"
          ],
          "steps": [
            "Review workflow design, business rules, controls, access, data handling, and exception paths.",
            "Verify testing evidence, rollback procedures, supervision model, and support readiness.",
            "Confirm ownership, runbooks, monitoring, change controls, and release approval.",
            "Record unresolved gaps, decisions, and accepted risks before release."
          ],
          "canvasId": null,
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": true
        },
        {
          "id": "automation-rollout-enablement-guide",
          "slug": "resources/automation-rollout-enablement-guide",
          "title": "Automation Rollout And Enablement Guide",
          "description": "Guidance for rolling out automations with user communication, onboarding, operating instructions, support paths, change management, and feedback loops.",
          "category": "guideline",
          "icon": "edit-document-outline",
          "order": 188,
          "outcomes": [
            "Enabled automation users and operators",
            "Rollout communication, onboarding, and support paths prepared",
            "Users and operators understand how work changes after automation release"
          ],
          "steps": [
            "Define rollout audiences, timing, communication channels, and training needs.",
            "Publish operating instructions, support paths, exception handling guidance, and escalation contacts.",
            "Plan transition support for users, operators, and process owners.",
            "Collect feedback after rollout and feed improvements into the backlog."
          ],
          "canvasId": null,
          "sourcePath": null,
          "sourceUrl": null,
          "contentMarkdown": null,
          "draft": true
        }
      ],
      "criteria": [
        {
          "id": "metrics-feedback-available",
          "title": "Relevant market signals, feedback, or operational insights are available to guide this capability opportunity.",
          "description": "Relevant market signals, feedback, or operational insights are available to guide this API opportunity.",
          "category": ""
        },
        {
          "id": "business-goals-defined",
          "title": "Business goals are defined.",
          "description": "Business goals are defined.",
          "category": ""
        },
        {
          "id": "market-research-done",
          "title": "Market research identifies capability opportunities.",
          "description": "Market research identifies API opportunities.",
          "category": ""
        },
        {
          "id": "stakeholder-approval",
          "title": "Relevant stakeholders agree this capability opportunity is worth exploring and prioritizing.",
          "description": "Relevant stakeholders agree this API opportunity is worth exploring and prioritizing.",
          "category": ""
        },
        {
          "id": "api-opportunity-documented",
          "title": "Capability opportunity is identified and documented.",
          "description": "Individual API opportunities are identified and documented.",
          "category": ""
        },
        {
          "id": "api-reusability",
          "title": "The capability addresses a clear business need and is reusable by its intended consumers.",
          "description": "The API meets a clear business need and is reusable for multiple API consumers.",
          "category": ""
        },
        {
          "id": "hide-backend-discrepancies",
          "title": "The selected interface provides an appropriate abstraction for consumers.",
          "description": "The API is intended to shield consumers from backend complexity and inconsistencies.",
          "category": ""
        },
        {
          "id": "value-prop-validated",
          "title": "The capability value proposition has been validated with business and consumer stakeholders.",
          "description": "The API value proposition has been reviewed and validated with the relevant business and consumer stakeholders.",
          "category": ""
        },
        {
          "id": "consumer-segments-identified",
          "title": "Consumer segments are identified.",
          "description": "API consumer segments (internal and external) are identified.",
          "category": ""
        },
        {
          "id": "api-roadmap-defined",
          "title": "A high-level implementation roadmap is defined.",
          "description": "High-level roadmaps for API development are established.",
          "category": ""
        },
        {
          "id": "architecture-patterns-validated",
          "title": "The chosen architecture, platform, and implementation style have been validated with the relevant architecture, security, and platform stakeholders.",
          "description": "The chosen API architecture and platform patterns have been validated with the relevant architecture, security, and platform stakeholders.",
          "category": ""
        },
        {
          "id": "design-reflects-business-value",
          "title": "The interface design and exposed capabilities trace back to business value and consumer needs.",
          "description": "The API design and exposed capabilities clearly trace back to business value and user needs.",
          "category": ""
        },
        {
          "id": "api-consistency",
          "title": "The interface design follows agreed design standards and conventions.",
          "description": "The API design follows our shared API product and design conventions.",
          "category": ""
        },
        {
          "id": "api-contract-tested",
          "title": "The interface contract has been validated and tested against functional and non-functional requirements.",
          "description": "The API contract is tested and meets functional and non-functional requirements.",
          "category": ""
        },
        {
          "id": "automation-workflow-validated",
          "title": "The workflow, rules, integrations, and relevant interface contracts have been validated and tested.",
          "description": "The workflow, rules, integrations, and relevant interface contracts have been validated and tested.",
          "category": ""
        },
        {
          "id": "api-description-available",
          "title": "The interface and its capabilities are documented clearly enough for review, audit, and onboarding.",
          "description": "The API and its exposed capabilities are described clearly enough for review, audit, and onboarding.",
          "category": ""
        },
        {
          "id": "audit-passed",
          "title": "The solution passes quality, security, compliance, and readiness checks.",
          "description": "The API passes compliance, security, and audit checks.",
          "category": ""
        },
        {
          "id": "audit-reports-shared",
          "title": "Audit findings and remediation decisions are shared with the relevant stakeholders.",
          "description": "Audit findings and remediation decisions are shared with the relevant stakeholders.",
          "category": ""
        },
        {
          "id": "api-ready-for-publishing",
          "title": "The capability is ready to be published or released through the selected delivery mechanism.",
          "description": "The API is ready to be deployed and exposed through the intended gateways and environments.",
          "category": ""
        },
        {
          "id": "api-documentation-ready",
          "title": "Consumer-facing documentation and onboarding materials are ready.",
          "description": "Consumer-facing API documentation is complete enough for publishing and onboarding.",
          "category": ""
        },
        {
          "id": "consumer-support-ready",
          "title": "Consumer onboarding, support, and communication processes are ready.",
          "description": "Registration, support, and communication processes are ready for API consumers.",
          "category": ""
        },
        {
          "id": "legal-compliance-clear",
          "title": "Legal, privacy, and compliance requirements for publishing or release are defined and understood.",
          "description": "Legal, privacy, and compliance requirements for publishing are defined and understood.",
          "category": ""
        }
      ]
    }
  }
}
