The white paper's central finding — "HoneyBook does not publish an open API" — went out on September 1. HoneyBook shipped an open MCP interface on August 19. Thirteen days stale on the day it was published.
In HoneyBook's own words, agents can create and update projects and client records, build a proposal, invoice or contract from the company's templates, publish it, and raise a payment request — with the member's permission, per resource. It went live inside ChatGPT on September 9 as one of sixteen tools in OpenAI's Small Business Collection.
And the line to read twice: HoneyBook says a venue-marketing agency has already used it to extend its own service into the booking process.
Credibility. That document went to Isaac. Isaac runs venues on HoneyBook, and HoneyBook's launch post names venues explicitly. Anyone who searches "HoneyBook API" this month finds the opposite of our key finding. Correct it before it is discovered, not after.
Architecture — and do not over-read the reversal. MCP is an agent-facing, member-authorized interface. It is not a server-to-server REST API with inbound webhooks, and it does not obviously give a Worker an unattended write path. The outbound webhook plus Zapier design may still be right. What changed is that it is now a choice, not the only path.
Strategy. Third vendor in twelve days to absorb a piece of the Vantage bundle — after SkySwitch and Intermedia, now from the CRM side.
Cloudflare shipped an emergency WAF release on September 10 for CVE-2026-75650 — unauthenticated remote code execution in Adobe Commerce and Magento Open Source, injecting PHP through style properties. New rule, action Block.
Cloudflare's guidance goes past patching: apply Adobe's hotfix and immediately rotate all potentially exposed encryption keys, integration tokens and credentials — patching alone does not remediate an existing compromise.
Vantage runs no Magento. The exposure, if any, is a client storefront. Run the inventory and write down the zero. If a client is on Magento, the rotation requirement makes this a billable incident-response engagement, not a patch ticket.
Cysurance named ESET its preferred MDR vendor. Buyers of ESET's MDR tiers automatically get a cyber warranty of $500,000 or $1 million, plus same-day cyber insurance with no underwriting. Our compliance and insurance motion still assembles MDR and insurance as separate conversations — a prospect who has seen this will ask what our stack warrants. The answer is a positioning paragraph, not a stack change. The discount figure is vendor-supplied; do not repeat it as market fact.
SCOUTz came out of stealth on September 10 — security sales intelligence for MSPs, 30-day open beta. It runs 156 check types against a prospect's external footprint and, with read-only consent, reviews their Microsoft 365 tenant agentless. That is the job of our hand-built Security Audit tool. Not a threat — a benchmark, and a free one.
And the sentence that ends the third daily running: every layer of the bundle is being commoditised by a vendor except the one trained on the venue's own data. That layer is unbuilt for the tenth consecutive week — seventy days as "the moat" without a line of code.