slug: fastly provider: Fastly generated_by: planning/capability-mapping/scripts/classify_capabilities.py model: claude-opus-5 frame: - Telecommunications min_confidence: 0.7 capability_model: source: https://github.com/vincentmakes/turbo-ea-capabilities license: CC-BY-4.0 attribution: Turbo EA Capabilities by Vincent Verdet — Turbo EA, https://github.com/vincentmakes/turbo-ea-capabilities, CC BY 4.0 notice: NOTICE edge_count: 27 edges: - tag: IAM Roles spec_file: fastly-iam-roles-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.9 evidence: GET /roles listRoles List IAM roles — "manage user invitations, roles, permissions, and service groups to control access to Fastly resources" reason: 'Plainly identity and access management: roles and permissions controlling access.' - tag: IAM Service Groups spec_file: fastly-iam-service-groups-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.85 evidence: POST /service-groups createServiceGroup Create an IAM service group — "manage ... service groups to control access to Fastly resources" reason: IAM grouping construct used for access control; maps to Identity & Access Management. - tag: IAM User Groups spec_file: fastly-iam-user-groups-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.85 evidence: POST /user-groups createUserGroup Create an IAM user group — "identity and access management (IAM) resources" reason: User group management for access control is IAM, not HR. - tag: WAF Active Rules spec_file: fastly-waf-active-rules-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.8 evidence: '"manage web application firewall rules that protect applications"; POST /waf/firewalls/{firewall_id}/versions/{n}/active-rules "Add an active WAF rule"' reason: Operations configure web-application-firewall rules that block SQLi/XSS attacks — a security control capability. Sits under Cybersecurity Management; no single L2 (detection/response vs architecture) is clearly named, so L1 only. - tag: WAF Firewalls spec_file: fastly-waf-firewalls-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.8 evidence: POST /waf/firewalls "Create a WAF firewall"; "web application firewall rules that protect applications delivered through Fastly's edge network" reason: CRUD over WAF firewall instances protecting web applications — a cybersecurity control capability rather than generic IT plumbing. L1 only as no specific L2 is evidenced. - tag: Secret Store spec_file: fastly-secret-store-api-openapi.yml capability_id: BC-4210.60 capability_id_l1: BC-4210 capability_name: Configuration & Secrets Management confidence: 0.78 evidence: POST /resources/stores/secret createSecretStore Create a secret store; schema SecretStore reason: Provisioning and deletion of secret stores holding runtime secrets consumed by edge compute services maps directly to Configuration & Secrets Management. recovered_from: sweep-20260828T235257Z-edges.json - tag: WAF Exclusions spec_file: fastly-waf-exclusions-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.78 evidence: '"Create a WAF exclusion"; "manage WAF firewall configurations, rule sets, and exclusions to defend against common web attacks"' reason: Tuning of WAF rule exclusions is web-application security control configuration, i.e. Cybersecurity Management. L2 not clearly determinable from the surface. - tag: Custom Dashboards spec_file: fastly-custom-dashboards-api-openapi.yml capability_id: BC-4220.20 capability_id_l1: BC-4220 capability_name: Observability Management confidence: 0.75 evidence: GET /observability/dashboards listCustomDashboards List Custom Dashboards reason: Operations manage dashboards under the /observability path, i.e. making the running service understandable in production — Observability Management. Some ambiguity as dashboards could also be read as analytics/BI. recovered_from: sweep-20260828T235257Z-edges.json - tag: Events spec_file: fastly-events-api-openapi.yml capability_id: BC-620.30 capability_id_l1: BC-620 capability_name: Threat Detection & Response Management confidence: 0.75 evidence: GET /ddos-protection/v1/events listDdosEvents List DDoS Events — "view attack insights including events, rules, and traffic statistics" reason: Attack event listing and inspection for DDoS incidents is security threat detection and response; the 'Events' tag here is security attack events, not generic platform events. - tag: Log Aggregations spec_file: fastly-log-aggregations-api-openapi.yml capability_id: BC-4220.20 capability_id_l1: BC-4220 capability_name: Observability Management confidence: 0.75 evidence: POST /observability/aggregations/logs aggregateLogData Aggregate Log Data reason: Operation sits under /observability and aggregates service log data, which is log-based observability of a running service. recovered_from: sweep-20260828T235257Z-edges.json - tag: Log Explorer spec_file: fastly-log-explorer-api-openapi.yml capability_id: BC-4220.20 capability_id_l1: BC-4220 capability_name: Observability Management confidence: 0.75 evidence: POST /observability/logs searchLogs Search Logs reason: Searching production service logs under an /observability path is log observability, not generic search plumbing. recovered_from: sweep-20260828T235257Z-edges.json - tag: WAF Rules spec_file: fastly-waf-rules-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.75 evidence: GET /waf/rules "List WAF rules"; "defend against common web attacks including SQL injection, cross-site scripting, and other OWASP Top 10 vulnerabilities" reason: Read-only catalogue of available WAF attack-detection rules; belongs to Cybersecurity Management. Thin surface (two GETs) so confidence moderate. - tag: Rules spec_file: fastly-rules-api-openapi.yml capability_id: BC-620.30 capability_id_l1: BC-620 capability_name: Threat Detection & Response Management confidence: 0.72 evidence: '"configure Fastly DDoS Protection and view attack insights including events, rules, and traffic statistics"; "Get All Rules For An Event"' reason: Rules here are DDoS mitigation rules tied to attack events — security detection and response, not business rules. - tag: Sudo Mode spec_file: fastly-sudo-mode-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.72 evidence: POST /sudo enableSudoMode Enable Sudo Mode reason: Elevation of a session to privileged mode is privileged access management within identity & access control; the spec description also frames the surface as 'identity and access management (IAM) resources'. recovered_from: sweep-20260828T235257Z-edges.json - tag: User spec_file: fastly-user-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.72 evidence: '"managing customer accounts, users, and identity and access management (IAM) resources"; "createInvitation Create a user invitation", "deleteUser Delete a user"' reason: User account lifecycle and invitation flows on a platform tenant are identity and access management (joiners-movers-leavers). The vendor's own description names IAM explicitly. - tag: ACL spec_file: fastly-acl-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.7 evidence: '"create and manage ACLs that can be used to control access to content at the edge. ACLs contain entries of IP addresses or CIDR ranges that can be referenced in VCL to allow or deny requests"' reason: Edge access control lists governing allow/deny of requests are an access-control mechanism; closest honest fit is cybersecurity identity & access management. Some ambiguity as this is service configuration on a CDN rather than enterprise IAM. - tag: ACL Entry spec_file: fastly-acl-entry-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.7 evidence: POST /service/{service_id}/acl/{acl_id}/entries createAclEntry; "manage large IP allowlists or blocklists" reason: Managing IP allowlist/blocklist entries used to allow or deny edge requests is an access-control capability. Same caveat as the ACL container tag — it is edge service configuration, not enterprise identity governance. - tag: Alerts spec_file: fastly-alerts-api-openapi.yml capability_id: BC-4220.20 capability_id_l1: BC-4220 capability_name: Observability Management confidence: 0.7 evidence: GET /alerts/definitions listAlertDefinitions ... GET /alerts/history listAlertHistory reason: Alert definitions and alert history over Fastly service metrics constitute monitoring/observability of a running service. Mapped to Observability Management with moderate confidence; could also be read as generic IT operations monitoring. recovered_from: sweep-20260828T235257Z-edges.json - tag: DDoS Protection spec_file: fastly-ddos-protection-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.7 evidence: PUT /enabled-products/v1/ddos_protection/services/{service_id} enableDdosProtection Enable DDoS Protection; GET .../configuration getDdosProtectionConfiguration reason: Enabling and configuring a DDoS mitigation control on a service is a cybersecurity control capability. Left at L1 because it is product enablement/configuration rather than clearly detection-and-response or architecture. - tag: Domain Inspector spec_file: fastly-domain-inspector-api-openapi.yml capability_id: BC-4220.20 capability_id_l1: BC-4220 capability_name: Observability Management confidence: 0.7 evidence: GET /v1/channel/{service_id}/ts/h/domains/{domain}/limit/{max_entries} getDomainInspectorRealtimeStats Get real-time domain metrics; schemas RealtimeMeasurements reason: Real-time per-domain request/bandwidth/error metrics for a running service is production observability telemetry, not business analytics. - tag: Logging BigQuery spec_file: fastly-logging-bigquery-api-openapi.yml capability_id: BC-4220.20 capability_id_l1: BC-4220 capability_name: Observability Management confidence: 0.7 evidence: POST /service/{service_id}/version/{version_id}/logging/bigquery createLogBigQuery Create a BigQuery logging endpoint — "logging endpoints that receive streamed log data from Fastly's edge network" reason: Configuration of log streaming destinations is observability (log) management for the running platform. - tag: Logging Datadog spec_file: fastly-logging-datadog-api-openapi.yml capability_id: BC-4220.20 capability_id_l1: BC-4220 capability_name: Observability Management confidence: 0.7 evidence: POST /service/{service_id}/version/{version_id}/logging/datadog createLogDatadog Create a Datadog logging endpoint reason: Creates/lists log-streaming endpoints to an observability backend; this is log observability configuration. recovered_from: sweep-20260828T235257Z-edges.json - tag: Logging Splunk spec_file: fastly-logging-splunk-api-openapi.yml capability_id: BC-4220.20 capability_id_l1: BC-4220 capability_name: Observability Management confidence: 0.7 evidence: POST /service/{service_id}/version/{version_id}/logging/splunk createLogSplunk Create a Splunk logging endpoint reason: Log forwarding to Splunk, a log analytics platform — observability log management. recovered_from: sweep-20260828T235257Z-edges.json - tag: Logging Syslog spec_file: fastly-logging-syslog-api-openapi.yml capability_id: BC-4220.20 capability_id_l1: BC-4220 capability_name: Observability Management confidence: 0.7 evidence: GET /service/{service_id}/version/{version_id}/logging/syslog listLogSyslog List syslog logging endpoints reason: Full CRUD over syslog log-delivery endpoints for a service version; log observability configuration. recovered_from: sweep-20260828T235257Z-edges.json - tag: Objects spec_file: fastly-objects-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: '"Fastly Object Storage is an S3-compatible cloud storage solution" with operations "Put Object", "Get Object"' reason: Object storage data-plane operations are cloud storage infrastructure, mapping to IT Infrastructure Management (compute, storage, network, cloud). - tag: Server Pools spec_file: fastly-server-pools-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: '"The Fastly Load Balancing API spreads traffic across multiple backends automatically"; "Create Server Pool", "Dynamic Server Pools that allow servers to be added or removed"' reason: Managing load-balancing pools of backend servers is network/compute infrastructure management, a Cross-Industry IT capability rather than anything telecom-network-specific. - tag: User Tokens spec_file: fastly-user-tokens-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.7 evidence: POST /tokens createToken Create an API token; DELETE /tokens/{token_id} revokeToken Revoke an API token reason: Issuance and revocation of API access credentials is access management. Ambiguity between enterprise IAM and developer-credential stewardship on a developer platform keeps confidence moderate. recovered_from: sweep-20260828T235257Z-edges.json