Run security-centred user research on how customers really deploy and operate the product, asking whether the hardening guide is applied correctly, whether security features work and resist real attacks in the field, and which features would lower the chance of compromise; results should feed changes to user flows, defaults, alerting and monitoring. Joint red team exercises with customers, on site, virtual or through privacy-preserving telemetry, are suggested.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.