Deployers should share with upstream developers, as far as possible while protecting commercially sensitive information and meeting privacy obligations, (a) issues, faults, failures, incidents and other observed risks the developer can address; and (b) any unexpected and unwanted bias arising from use of the system.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.