Game-Changer Watch · Sept 13, 2026

A partner shipped an open API — and our white paper says they didn't

Game-Changer Watch · Sunday, September 13, 2026 · a ~3-minute catch-up
Seven cards, about 30 seconds each. One correction to make before a client finds it, and one five-minute check now two days out.
EDGEPOINTE · VANTAGE
The headline · HoneyBook

The sentence the Outbound Wing white paper was built on was already false when we wrote it. Game-changer

The white paper's central finding — "HoneyBook does not publish an open API" — went out on September 1. HoneyBook shipped an open MCP interface on August 19. Thirteen days stale on the day it was published.

In HoneyBook's own words, agents can create and update projects and client records, build a proposal, invoice or contract from the company's templates, publish it, and raise a payment request — with the member's permission, per resource. It went live inside ChatGPT on September 9 as one of sixteen tools in OpenAI's Small Business Collection.

And the line to read twice: HoneyBook says a venue-marketing agency has already used it to extend its own service into the booking process.

Bottom line: a partner already inside our architecture diagrams became a platform, and nobody was watching that lane.
Three consequences · not the same size

Credibility is the urgent one. The architecture may not need to change at all. Position

Credibility. That document went to Isaac. Isaac runs venues on HoneyBook, and HoneyBook's launch post names venues explicitly. Anyone who searches "HoneyBook API" this month finds the opposite of our key finding. Correct it before it is discovered, not after.

Architecture — and do not over-read the reversal. MCP is an agent-facing, member-authorized interface. It is not a server-to-server REST API with inbound webhooks, and it does not obviously give a Worker an unattended write path. The outbound webhook plus Zapier design may still be right. What changed is that it is now a choice, not the only path.

Strategy. Third vendor in twelve days to absorb a piece of the Vantage bundle — after SkySwitch and Intermedia, now from the CRM side.

Bottom line: one paragraph of correction, half an hour of reading — not a rebuild.
What to do · this week

Rewrite the paragraph so the argument rests on a principle instead of an absence.

a · Correct §2
Say what is true: HoneyBook publishes no conventional REST API or inbound webhook, and as of Aug 19 exposes an MCP interface with member-authorized read and write. The outbound webhook was chosen because it keeps Vantage the system of record. That version is stronger, not weaker.
b · Half-hour read
Settle one question in writing: can a Vantage Worker write a lead into a tenant's HoneyBook unattended, or does MCP require a member-authorized session? If not, close it permanently so it is never re-researched.
c · Use the number carefully
"97% of event venue managers struggle with disorganized booking systems" is a good opener — vendor-reported, no methodology. Attribute it to HoneyBook out loud.
Bottom line: the cheapest credibility save on the board, and it fits in one sitting.
Security · act now

Emergency WAF release for an actively exploited Magento RCE. Our exposure is nil — record the zero. Act now

Cloudflare shipped an emergency WAF release on September 10 for CVE-2026-75650 — unauthenticated remote code execution in Adobe Commerce and Magento Open Source, injecting PHP through style properties. New rule, action Block.

Cloudflare's guidance goes past patching: apply Adobe's hotfix and immediately rotate all potentially exposed encryption keys, integration tokens and credentials — patching alone does not remediate an existing compromise.

Vantage runs no Magento. The exposure, if any, is a client storefront. Run the inventory and write down the zero. If a client is on Magento, the rotation requirement makes this a billable incident-response engagement, not a patch ticket.

Bottom line: same shape as the Next.js RCE this board got right. Inventory, then close it.
Two positioning items

Security-plus-warranty is now bundled one tier above us, and the manual audit pitch became a product. Watch

Cysurance named ESET its preferred MDR vendor. Buyers of ESET's MDR tiers automatically get a cyber warranty of $500,000 or $1 million, plus same-day cyber insurance with no underwriting. Our compliance and insurance motion still assembles MDR and insurance as separate conversations — a prospect who has seen this will ask what our stack warrants. The answer is a positioning paragraph, not a stack change. The discount figure is vendor-supplied; do not repeat it as market fact.

SCOUTz came out of stealth on September 10 — security sales intelligence for MSPs, 30-day open beta. It runs 156 check types against a prospect's external footprint and, with read-only consent, reviews their Microsoft 365 tenant agentless. That is the job of our hand-built Security Audit tool. Not a threat — a benchmark, and a free one.

Bottom line: the honest question — does our audit show a prospect anything 156 automated checks don't?
The stack · and the one thing nobody is building

The zone check is two days out and has never been run. Sixth consecutive stack. Overdue

0 · Ship it
The telephony proof of concept passed its gate, sits dormant behind a flag, and is still not pushed. Three vendors have shipped a receptionist since it was finished.
1 · The zone check
September 15. Two days. Five minutes. Sixth consecutive stack. There is no version of this week where it is not done.
2 · The white paper
One paragraph, in a client's hands, wrong on its own headline finding.
3 · Magento inventory
Record the zero.

And the sentence that ends the third daily running: every layer of the bundle is being commoditised by a vendor except the one trained on the venue's own data. That layer is unbuilt for the tenth consecutive week — seventy days as "the moat" without a line of code.

Bottom line: two of the top four take minutes. The one that takes months is the one that matters.
Card 1 / 7 · ~20s