A hard fail SPF record is used when specifying authorised email servers (or lack thereof) for an organisation's domains (including subdomains).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.