# Gusto: 71 point Door Gap
- Site: gusto.com
- Scanned: 2026-09-10
- Scan type: Basic scan
- Business type: b2b_saas
- Report: https://www.seconddoor.io/r/gusto-mr5wj8
- Scanner version: 48
- Scanner release: ea296a9
- Scoring methodology: 1
- Evidence schema: 1
1 human and 2 agent dimensions measured from the pages checked; remaining dimensions are not scored.
## Scores
| Measure | Score |
| --- | --- |
| Humans | 80/100 (1/4 dimensions) |
| Agents | 9/100 (2/6 dimensions) |
| Composite | 45/100 |
| Door Gap | 71 points |
The human score is the mean of the measured human dimensions, the agent score the mean of the measured agent dimensions, and the Door Gap the difference between them.
## What the machine actually did
The scanner recorded successful observations for 3 of 9 checks, but could not find a contact route for machines. It came up empty on 5 other checks too. 6 checks could not be measured; see the report limitations.
- ok      find out whether machines are welcome
- ok      read the site's own guide for language models
- missing find a contact route for machines
- missing find an MCP manifest at the standard paths checked
- missing find an agent plugin manifest
- missing find out whether verified agents are recognised
- missing find a machine readable API spec
- missing read the developer documentation
- ok      walk the way a visitor would, to a signup form or a product
## What a visitor meets
1. **Entry observation** (observed). Primary entry is "Create account Create free account". 2 steps from the homepage. 8 fields, 7 marked required in the visible form. 1 sign in option: google. 7 of 8 visible entry-form inputs carry validation attributes; submission was not tested.
## Top issues
1. **No OpenAPI specification was identified at the 6 standard paths checked.** (programmatic_onboarding)
The evidence and the recommended fix for each are on the report page: https://www.seconddoor.io/r/gusto-mr5wj8
## Files generated from this scan
- **Let verified assistants through** at `notes`, 1 hour, developer. Verify: On a subsequent scan, compare the same endpoint and client response. An unavailable check remains unresolved.
- **Machine interfaces: where you stand** at `notes`, 10 minutes, no developer needed. Verify: The next scan finds the interface you published answering at its well-known path, and that check passes.
- **security.txt** at `/.well-known/security.txt`, 10 minutes, no developer needed. Verify: The next scan fetches /.well-known/security.txt as text and the security.txt check passes.
Each file is written from what this scan found on the site. The content is in the JSON once the evidence is opened: https://www.seconddoor.io/api/reports/gusto-mr5wj8
## The agent door
- **machine_discoverability** not measured. Not measured: an access refusal or challenge prevented our scanner from reading the required page.
- **programmatic_onboarding** 10/100. No API interface was identified through the discovery paths and homepage links checked.
- **pricing_legibility** not measured. Not measured: an access refusal or challenge prevented our scanner from reading the required page.
- **agent_aware_instrumentation** 8/100. No MCP manifest was identified at the discovery paths checked.
- **machine_fetchable_trust** not measured. Not measured: an access refusal or challenge prevented our scanner from reading the required page.
- **commercial_rails** not measured. Not measured: an access refusal or challenge prevented our scanner from reading the required page.
## The human door
- **steps_to_first_value** 80/100. A signup form was reached in 2 steps from the homepage.
- **required_fields** not measured. Not measured: our scanner could not identify the required evidence on the pages checked.
- **verification_walls** not measured. Not measured: this read-only scan did not submit the form or perform the action needed to test this behavior.
- **error_recovery** not measured. Not measured: this read-only scan did not submit the form or perform the action needed to test this behavior.
---
Scored by SecondDoor. Method: https://www.seconddoor.io/methodology
Scan another site: https://www.seconddoor.io
Rate an issue or this report: POST https://www.seconddoor.io/api/feedback, or the rate_fix tool on https://www.seconddoor.io/api/mcp
