Every report should be followed from arrival to closure under a case identifier, with its current status and the messages exchanged, so the vendor can show what became of each one; ISO/IEC 30111 7.1.3 asks for a record to be kept of every vulnerability and suspected vulnerability that comes in, from any source.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.