DocsGetting started / Reading your scan report

Reading your scan report

A scan report is one page about one website: what an AI assistant could do there, where the number came from, and what to change. This page walks it top to bottom.

The report is generated, not written. Nothing on it is an opinion: every line is a check that passed, failed or warned, and every number comes from a recorded scan that can be re-read.

There are two kinds of report. A full one, which opens when you scan your own site. And a public one: every business in the index has a page at /b/<domain> with its score and top findings. The fifteen sample reports from 25 August 2026 have been replaced by that index, and their old /scan/<slug> addresses forward to it at /businesses.

One report, top to bottom, and the one thing missing from it

The name, withheld by defaultWhere a business name would sit, an unnamed report carries a descriptor and a placeholder host, "plumber", shared by more than one site in the sample. The dashed box is that space, left empty by design. A report is named only where a recorded, reviewed permission exists for it.

  1. The number and the verdictTop of the pageA score out of 100, a grade, and one sentence saying what the grade means for a customer sent here by an assistant. Under it: when it was scanned and which scanner ran it.
  2. This report at a glanceBetween the score and the findingsFour tiles, none of them a new number: actions found and how many are blocked, both counted over the rows below; pages scanned, always one, since every scan reads a single page; and the date it was scanned.
  3. What an agent can do here, and how ready the site is01A tab bar, not a flat run of sections: Blockers (one row per way in that is not agent-callable, and what blocks it, drawn open below), All actions (every row, callable or not), Readiness by area (the five categories behind a severity bar and, once a second scan exists to compare, a radar chart) and Pages (the one page the scan read).
  4. The fix list03Everything with a named remedy, in the order the score reads them. Free, and the whole list, the part to treat as useful.
  5. How this compares04This site against the sample mean, the best and the lowest score, and a table by vertical. The sample is the 25 August 2026 run; the sample reports that once showed it were retired on 9 October 2026.
  6. What this report is, and what it is notAfter the findingsThree of its five one-line verdicts, plus a link to the full text below, closing the page now, not opening it. Reproduced in full as section 05 below.
  7. What was removedFoot of the pageThree lines on every unnamed report: the name and address withheld; phone numbers and widget URLs withheld; the raw markup withheld. A named report states its removal path instead of the first line.
  • What every published report carries: the dial, the verdict, the section headings and the rules between them
  • The fix list, the one part of the report written for you to act on
  • A thing the scanner found on the site, a form, a way in, drawn as its own shape, not ours
  • A field removed before publication: a dashed box where a name would be
The shape of every published report, drawn, and none of the fifteen in particular: the dial has no number, the rows carry no words, the comparison axis has no scale, and the box where a name would sit is empty. The parts are in the order the report renders them, the limits sit after the comparison, not under the score, and the numerals are this drawing’s, not the report’s kickers, which are printed beside each part.

A score out of 100, a grade, and one sentence saying what the grade means for a customer sent here by an assistant. Underneath: when it was scanned, and which version of the scanner did it.

The grade bands are fixed at 70 and 40. agent-ready at 70 and above, partially ready from 40 to 69, invisible to agents below 40.

01. What an agent can actually do here

Every way in the scanner found on the page it fetched, and whether software could drive it. This is the section that decides whether a customer sent by an assistant becomes a job.

On the page this sits behind a tab bar rather than a flat run of sections: Blockers (only the actions that are not agent-callable, with their reasons), All actions (every one, callable or not, the table below), Readiness by area (section 02) and Pages, the one page this reads, named plainly rather than as a per-page table the scanner has never produced, since "It measures one page, fetched once, read-only" is already this report's first honest limit (section 05, below). Switching needs no script, it is a native radio group under the hood, so it still works with scripts blocked, the same reader the rest of the report is written for.

Each row is one detected action. Its columns:

Columns on an action row
FieldWhat it holds
kindOne of booking, quote, contact, callback, phone or widget, rendered as "Booking", "Quote request", "Contact form", "Callback request", "Phone link", "Booking widget".
labelThe short name of the thing found, "booking form", "Cliniko booking widget".
detailFor a form, the number of fields on it. For a phone link, the link itself, which is why it is withheld on a published report.
agentCallableTrue only on positive evidence: a declared tool, an advertised endpoint, a published catalogue, a known booking widget, or a form complete enough to fill. There is no "nothing looked broken" route to true.
callableViaPresent only when callable. Which of the five routes earned it.
blockersPresent only when not callable. Exactly what is missing, in plain words. This is the free fix list at action level.
A tel: link is never agent-callable. It hands off to a human, which is a real customer path and not an action software can complete.

One action row from a published report

{
  "kind": "booking",
  "label": "booking form",
  "detail": "8 fields",
  "agentCallable": false,
  "blockers": [
    "a CAPTCHA on this page blocks legitimate agents"
  ]
}
Copied unchanged from the 25 August 2026 sample bundle, the Quay Dental Clinic report. An action row carries no identity field to substitute, this one reads the same whether the report it belongs to is named or not.

That row is worth reading twice. The form has eight fields, every one of them fine, and the action is still closed to agents, because a CAPTCHA sits in front of it. The score is not what stops a booking. The wall at the end of the form is.

If the section is empty, the scanner found no way in at all on the page it fetched: no form, no widget, no phone link. Two of the fifteen sampled sites are in that state.

02. Where the score came from

Five categories, twenty points each, with every individual check listed underneath as a pass, a warning, a failure or a note. Each category also carries one sentence explaining what it is measuring, aimed at an owner rather than a developer.

This is the "Readiness by area" tab. Above the five categories: a severity spectrum bar, its segment widths proportional to the real count of failing, warning and clear checks across all five, so the mix is visible before reading a single one. Above that again is either a radar chart of the five scores with a previous scan dashed behind it, or, on every report today, since none of the fifteen carries a second scan of the same subject to compare against, a plain list of the same five numbers.

The five categories on a report
CategoryWhat it measures
Crawlability and discoveryWhether an agent is allowed in at all, and whether the site tells it where things are.
Structured dataWhether the business facts, trade, hours, phone, address, services, are published in a form software can read, rather than only drawn on the page.
Action affordancesWhether there is anything on the page an agent could act on: a booking widget, a form, a number.
Form qualityWhether the forms are built so software knows what goes in each box and can press send.
Agent interfaceWhether the site publishes any of the 2026 agent standards, WebMCP, an MCP endpoint, an ARD catalogue, or leaves an agent to scrape and guess.
The full point allocation for each category is on the agent-readiness score page.

Findings carry a status and, where any tooling counts them, a stable code. The prose of a message is for humans and may be reworded; nothing should ever be tallied by matching message text.

03. The fix list

Everything the scanner found that has a named remedy, in the order the score reads them. These are instructions for whoever maintains the site. They are free, and they are the whole list, nothing is held back for a paid tier.

On a published report the fix text is rewritten on the way out, and the reason is worth stating plainly. Six fix strings in the 25 August scan evidence are written in the first person and advertise a hosted layer, a snippet and verified actions that do not exist. On a private report handed over by a person who explains the state of things, that is a sales conversation. On a public page it is a claim we cannot support. So the publication path rewrites all six into instruction-only text, and refuses to publish a report in which one survives.

The wording was corrected at source in the scanner on 26 August 2026, so any scan run after that date produces instruction-only text directly. The fifteen reports from the 25 August run were produced the day before and carried the old wording. They have since been retired, so no page shows it.

The WebMCP fix reads: "Declare your booking and quote actions as WebMCP tools on document.modelContext, keeping navigator.modelContext as a fallback for older builds, via the @mcp-b/global polyfill. WebMCP is a W3C Community Group draft and a Chrome 149 origin trial; no browser has shipped it to stable."

document.modelContext is the current surface and navigator.modelContext is a deprecated fallback. Neither is a shipped browser API, so following the advice today means loading the polyfill.

04. How this compares

The same scanner, the same day, run over a sample of service businesses found the way a customer’s agent would find them: plain searches for a plumber, a physio and a real estate agent. Nobody was screened for looking bookable.

The section shows this site against the sample mean, the best and the lowest score in the sample, and a per-vertical table of mean score and how many sites had an action an agent could call directly.

The sample this compares against
VerticalSitesMeanAgent can call directly
Trades558.01
Clinics547.60
Real estate531.40
All1545.71

05. What this report is, and what it is not

This block is on every report. It is reproduced here because it is the part a reader skimming a number will skip.

  • It measures one page, fetched once, read-only. The scanner requested the page and read the HTML it was handed. It did not run scripts, click anything, fill a field or submit a form, and it did not crawl the rest of the site. A site with a booking flow two clicks deep scores as if it were not there, because that is what an agent reading the fetched page gets.
  • It understates most sites, and we know by how much. Opening the same sample in a real browser, rendering, waiting for scripts, clicking, following a link, reached actions a fetch of the entry page could not see, on almost every site in it. Discovery is not the wall. The wall is the CAPTCHA and the consent tick at the end of the form. And a browser agent that gets past the wall is still acting uninvited: the business never agreed to it, cannot set a limit on it, and gets no record it happened.
  • Read a score as a direction. Treat a category score as a direction, not a verdict, and treat the fix list as the useful part.
  • The owner decides what an agent can do. An agent can find the business through frontlatch.com/mcp and read what its site offers. Once the owner claims the listing and switches an action on at /app, a matching request arrives as a job card by email, and nothing books until the owner accepts it.
  • No action ever fires without the owner turning it on. An owner proves they control the domain at /claim, then in /app switches an action on, chooses which agents may call it and sets a limit. Test mode is the default.

What was removed, and why these are named

Every published report states its own redactions rather than leaving a reader to wonder. Phone numbers and booking-widget URLs are withheld on every published report, named or not, and so is the raw page markup, the scanner’s evidence trail. The business name and website address are withheld too, unless a recorded, reviewed permission names that business.

The businesses in the sample are real trading companies. They did not ask to be scanned, they have no right of reply on these pages, and the instrument that scored them is early enough that we publish its defects, which is exactly why naming was default-off until we set the condition under which it is fine: a recorded, reviewed permission for that specific business, with a working removal path. The fifteen sample report pages were retired on 9 October 2026; naming now follows the index, where a business can be removed at its /b/<domain> page.

The lowest score in the 25 August sample was 12 out of 100, and it was real. That sample’s report pages are retired; the figure stays as the run’s record.

The removal is structural rather than a find-and-replace pass. Identifying fields are rebuilt from a safe vocabulary instead of filtered, and any free-text field that does not match a known-safe shape is replaced wholesale. A final check throws on a surviving hostname, business-name token or phone number that has no matching recorded permission before anything can be published, and the test suite greps the generated bundle for every one of those and fails if a single one survives without one.

On an unnamed report the subject a reader sees is an editorial descriptor and a placeholder host, "plumber", <plumber>.com, and descriptors are deliberately shared by more than one site in the sample, so a descriptor never narrows to one business on its own. On a named report the descriptor field carries the real trading name instead, that is how the retired sample reports for named businesses worked.

Where the numbers came from

The report pages render a stored scan; they never re-score anything. That scan carries its own provenance, so a claim on a page can always be walked back to the run that produced it.

The bundle describing itself

{
  "scanner": "agent-readiness-scanner",
  "scannedAt": "2026-08-25T10:42:04.906Z",
  "sites": 15,
  "scanned": 15,
  "failed": 0,
  "politeness": "Read-only. Sequential, 2000ms between sites, 45000ms per-site timeout. No form was filled and nothing was submitted."
}
Copied unchanged from the generatedFrom block of the published bundle.

The fifteen sample reports come from one run on 25 August 2026, and they are not re-scored. Every business in the index has its own live page at /b/<domain>, listed from /businesses. To scan any other site, go to /get-scanned, enter a domain, and the report opens in the same tab when the scan finishes. If you have claimed the domain, the Overview in /app has a Share your score button. It copies a public link, /score/<id>, that shows the host, the score, a one-line verdict and the top three findings, and nothing else. The page is not indexed by search engines, and Stop sharing in the same place makes the link return 404.

See what an AI agent can do on your site.