# monday.com: agent door 70, human door not measured
- Site: monday.com
- Scanned: 2026-09-10
- Scan type: Basic scan
- Business type: b2b_saas
- Report: https://www.seconddoor.io/r/monday-r7bvuy
- Scanner version: 49
- Scanner release: c49d1def936f56a5ab0871f38c5e6412433ec37a
- Scoring methodology: 1
- Evidence schema: 1
0 human and 5 agent dimensions measured from the pages checked; remaining dimensions are not scored.
## Scores
| Measure | Score |
| --- | --- |
| Humans | not measured |
| Agents | 70/100 (5/6 dimensions) |
| Composite | 70/100 |
Agent door only. The human door could not be measured on this scan. A Door Gap needs both doors, so this scan does not report one.
## What the machine actually did
The scanner recorded successful observations for 10 of 14 checks, but could not find a contact route for machines. It came up empty on 3 other checks too. 1 check could not be measured; see the report limitations.
- ok      reach the site at all
- ok      find out whether machines are welcome
- ok      ask whether the door opens for requests carrying the AI crawlers' names
- ok      read the site's own guide for language models
- ok      find out what pages exist
- missing find a contact route for machines
- missing find an MCP manifest at the standard paths checked
- missing find an agent plugin manifest
- missing find out whether verified agents are recognised
- ok      read the homepage as data rather than as a page
- ok      find a machine readable API spec
- ok      read the developer documentation
- ok      read the prices without running JavaScript
- ok      find a comparison page worth citing
## What a visitor meets
1. **Entry observation** (unmeasured). The signup page answered an automated browser with an automated traffic challenge. The form behind that response was not observed.
## Top issues
1. **No valid security.txt was identified at /.well-known/security.txt.** (machine_fetchable_trust)
   - Evidence: /.well-known/security.txt: not found (404)
   - Evidence: Checked URL: https://monday.com/.well-known/security.txt
   - Fix: Publish /.well-known/security.txt with a contact route.
The full report is at https://www.seconddoor.io/r/monday-r7bvuy
## Files generated from this scan
- **pricing.md** at `/pricing.md`, 20 minutes, no developer needed. Verify: The next scan fetches /pricing.md as text and records pricing as machine readable.
- **security.txt** at `/.well-known/security.txt`, 10 minutes, no developer needed. Verify: The next scan fetches /.well-known/security.txt as text and the security.txt check passes.
Each file is written from what this scan found on the site. The content is in the JSON once the evidence is opened: https://www.seconddoor.io/api/reports/monday-r7bvuy
## The agent door
- **machine_discoverability** 100/100. Robots.txt explicitly names 6 AI crawler tokens; policies differ by token. On its first visit, our browser read the homepage. No user agent rule refused the tested retrieval crawler names.
- **programmatic_onboarding** 62/100. A machine readable API spec is published. OAuth authorization metadata is published.
- **pricing_legibility** 96/100. 48 prices are readable without JavaScript. An enterprise tier routes to sales, which is standard practice and not counted against the score. The plans are published as Offer structured data too. The pricing page carries FAQ markup.
- **agent_aware_instrumentation** 52/100. No MCP manifest was identified at the discovery paths checked. Robots.txt explicitly names 6 AI crawler tokens; policies differ by token. OAuth authorization-server metadata is published; this alone does not identify an MCP endpoint.
- **machine_fetchable_trust** 40/100. No security.txt was identified at the checked path. The homepage answers automated requests.
- **commercial_rails** not measured. Not measured: an access refusal or challenge prevented our scanner from reading the required page.
## The human door
- **steps_to_first_value** not measured. Not measured: an access refusal or challenge prevented our scanner from reading the required page.
- **required_fields** not measured. Not measured: an access refusal or challenge prevented our scanner from reading the required page.
- **verification_walls** not measured. Not measured: an access refusal or challenge prevented our scanner from reading the required page.
- **error_recovery** not measured. Not measured: an access refusal or challenge prevented our scanner from reading the required page.
---
Scored by SecondDoor. Method: https://www.seconddoor.io/methodology
Scan another site: https://www.seconddoor.io
Rate an issue or this report: POST https://www.seconddoor.io/api/feedback, or the rate_fix tool on https://www.seconddoor.io/api/mcp
