Agent Readiness Is Not AI Visibility: What Cloudflare's Scanner and Bing's Citation Share Each Actually Measure

Analytics & Measurement | 9 | Published:

By , Founder of The Lmo7 Agency

Two free tools landed within weeks of each other and they answer opposite questions. Cloudflare's scanner checks whether agents can technically reach your site. Bing's Citation Share shows whether AI actually cites you. Passing one says nothing about the other, and only one is close to revenue.

Agent Readiness Is Not AI Visibility: What Cloudflare’s Scanner and Bing’s Citation Share Each Actually Measure

By Stephen Honight, Founder of Lmo7

Two free tools landed within weeks of each other this summer and they answer opposite questions. One tells you whether an AI agent can technically interact with your site. The other tells you whether AI systems are actually citing you. Both are being talked about as “AI readiness” tools. They are not measuring the same thing, and treating them as if they are is going to send a lot of brands chasing the wrong number.

The first is Cloudflare’s agent-readiness scanner at isitagentready.com. The second is Bing’s Citation Share, now rolling out inside Bing Webmaster Tools. My sense is that most teams will run both, see a red cross on one and a percentage on the other, and assume they are two views of the same problem. They are not. One is plumbing. The other is the scoreboard. You can pass every plumbing check and never get recommended, because recommendation is won somewhere else entirely.

Let me walk through what each tool actually checks, then what I would do with the hour you have this week.

What Cloudflare’s scanner is really testing

Cloudflare’s scanner runs your domain against around twenty emerging standards grouped into five categories: discoverability, content accessibility, bot access control, API and authentication and MCP, and commerce. It is a useful inventory of where the agentic web is heading. It is not a to-do list you should work through top to bottom.

I ran lmo7.com through it. It failed on a long list: Link headers, DNS-AID, markdown negotiation, Content Signals, API catalog, OAuth discovery, OAuth Protected Resource, Auth.md, MCP Server Card, an agent skills index, WebMCP. Seeing that many red marks, the natural reaction is to open a ticket for each one. That would be a mistake for most brands.

Here is the mechanism. Most of those checks are for standards that are barely off the drawing board. DNS-AID is an IETF draft. Auth.md is a proposal from WorkOS. API catalog and OAuth metadata only mean anything if you run a public API, which a consumer brand’s brochure site does not. The MCP Server Card and the agent skills index are pre-standard. Agent consumption of these today is close to zero. Failing them right now costs you nothing, because nothing is out there reading for them yet. If you spend a sprint building an MCP Server Card for a site that sells kitchenware, you have optimised for a reader that has not shown up.

Two of the checks are worth taking seriously. Both because there is real, observable adoption behind them.

The first is markdown negotiation. This is a Cloudflare feature where your server can hand an agent clean markdown instead of full HTML when the agent asks for it with an Accept: text/markdown header. Suganthan ran independent tracking on this for 44 days and logged 1,421 markdown-negotiated requests from several independent systems, with Anthropic infrastructure making up roughly 35% of that traffic. As of February 2026, Claude Code, OpenCode and Cursor all send that header by default. So this is not a speculative standard. There are real agents asking for markdown right now, and the number is growing.

One honest caveat, because it matters. Markdown negotiation does not improve your citation rate. There is no evidence for that and I would not let anyone sell it to you on that basis. What it does is make your content cheaper and cleaner for an agent to parse, which lowers token cost and reduces the chance the agent trips over your page furniture. It is a parseability win, not a visibility win. Worth doing, worth being precise about why.

The second real check is Content Signals in robots.txt. This is a genuine standard, advisory rather than enforced, that lets you state how AI systems may use your content. And this is where I would stop and read the scanner’s own advice very carefully, because its example fix is precisely backwards for a brand that wants to be recommended.

The scanner’s suggested line is Content-Signal: ai-train=no, search=yes, ai-input=no. Read what ai-input=no is asking for. It is telling AI systems not to use your content as input when they form answers. For a brand whose entire goal is to be pulled into an AI answer and recommended to a shopper, that is the opposite of what you want. If you copy that example straight off the scanner, you have just politely asked the models to leave you out of the conversation. My recommendation would be to set these permissive across the board, or leave them absent entirely, because absence means no restriction. This is one of those cases where a well-meaning default does real commercial damage if you follow it without thinking.

There are two more sections on the scanner worth a mention. WebMCP is a W3C incubation with an early Chrome preview, built for transactional sites where an agent needs to take actions on the page. Irrelevant for a brochure site today. On the twelve-month radar for D2C brands with real checkout flows. And the commerce protocols, x402, ACP, UCP and MPP, have near-zero adoption right now but they are the section D2C brands should actually watch, because that is where agentic checkout lands over the next year. I will come back to that.

Implementation note from our own run. lmo7.com sits on Replit, not behind Cloudflare’s toggle, so markdown negotiation had to be specced as app-level middleware rather than flipped on with a switch. We handed that brief over. At the time of writing it is specced, not confirmed shipped, so I will not claim we have it live. The point stands either way: of that whole red list, the markdown fix and the Content Signals line are the only two I would touch this quarter.

What Bing’s Citation Share is really testing

Now the other tool, and the other question.

Bing has started rolling out Citation Share inside the AI Performance dashboard in Bing Webmaster Tools. Microsoft is shipping four features together: Citation Share, Intents, Topics and Compare. Citation Share is the headline. It shows your site’s percentage of all the citations for a specific grounding query. If a query pulls ten citations into an AI answer and three of them are yours, that is a 30% Citation Share. Intents classifies the grounding queries by type, informational, commercial, research and so on. Topics clusters related queries thematically. Compare overlays one period against another so you can see movement.

This is a different animal from the Cloudflare scanner. The scanner asks “can an agent technically deal with your site”. Citation Share asks “is an AI system actually choosing you when it answers a real question”. That second question is much closer to whether you are winning.

A few honest limits, because Microsoft is upfront about them and I would keep clients equally upfront. Microsoft calls Citation Share observational. It does not expose competitor domains, so you see your own share but not who is taking the rest. And it does not represent traffic share, so a 30% Citation Share is not 30% of the clicks or the revenue. It is a grounding-citation measure inside the Bing and Copilot ecosystem only. That last point matters. This is one engine’s view. It sits alongside a proper Share-of-Model programme that tracks ChatGPT, Gemini, Perplexity and Rufus, it does not replace it. Google is testing its own AI visibility reporting in Search Console, which is a different ecosystem measured a different way again.

But here is why I am genuinely pleased to see it. It is the first free, first-party share-of-citation metric from a major AI search provider. Until now, measuring whether AI systems cite you meant paying for a prompt-panel tool or running your own tracking. Now one slice of it is free, and it is broken out by intent, which means you can look specifically at commercial-intent queries, the ones closest to a purchase. That is the number I would spend time on.

Readiness is the plumbing, Citation Share is the scoreboard

So put the two side by side. Cloudflare’s scanner is a readiness check. Bing’s Citation Share is a visibility measure. Readiness is not visibility, and this is the distinction most brands are about to blur.

You can pass every protocol check on the scanner and still get cited by nobody. The reverse happens too, and I have the cleanest possible proof point sitting on my own domain. lmo7.com scores 88 out of 100 on AI readability. Technically the site is in good shape, clean structure, decent schema, content an AI can parse without effort. And it is functionally invisible in AI answers, because our domain authority is a 9 and we have close to no organic footprint. The plumbing is excellent. The recommendation is not there. Readiness did not buy us visibility, because the two are set by different levers.

Veloforte, one of our clients, sits at the opposite corner and makes the same point from the other side. Their domain rating is 53 with real search presence, but their AI readability came in around 38 out of 100. Authority present, parseability weak. Neither of us is winning on both axes yet, and that is exactly the point. Readiness and visibility are two separate problems that need two separate tracks of work.

This maps cleanly onto how we frame every engagement at Lmo7. There is a quick-wins track and a long game. The quick wins are content clarity, PDP structure, schema, the readiness fixes, the things you can ship in weeks. The long game is authority, citations, digital PR, third-party mentions, reviews, expert sources, the things that actually decide whether an AI chooses you. The Cloudflare scanner lives almost entirely in the quick-wins track. Bing’s Citation Share is the first time the long game has a free scoreboard attached to it.

And when the long game moves, you can see it. Trip Drinks came to us sitting seventh on average position across the major models. Over 60 days of site signals work, content upgrades and citation-source optimisation, they moved to third, and AI referral traffic rose 33%. Haleon’s Voltarol, in its category, showed a 100% mention rate and the number one average position. Those are visibility outcomes. No amount of passing the readiness scanner would have produced them. They came from the authority and content side of the work, the side Citation Share now lets you watch for free in one engine.

The bit D2C brands should keep half an eye on

One more thing from the scanner worth flagging, because it is the part that is premature today and will not be for long.

The commerce section, x402, ACP, UCP and MPP, is where agentic checkout gets built. Right now adoption is near zero, so I would not act on it. But if you are a D2C brand running your own store, this is the section to watch over the next twelve months, because when agents start completing purchases rather than just recommending them, these are the rails they will run on. WebMCP sits in the same bucket. Irrelevant for a brochure site, relevant the moment an agent needs to do something on your checkout page. For most brands this is a “note it, revisit next quarter” item, not a “build it now” one. But it is the one part of the premature list that has a real clock on it.

So what should you do next

Here is the practical order I would work in this week.

Ignore most of the Cloudflare red list. DNS-AID, Auth.md, API catalogs, MCP Server Cards, agent skills indexes, these are draft standards with near-zero readers. Failing them costs nothing today. Do not let a scanner full of red crosses set your roadmap.

Ship the one readiness fix that has real adoption. Enable markdown negotiation so the agents already asking for markdown get a clean parse. Be clear internally about why: it lowers parsing cost, it does not raise your citation rate.

Set your Content Signals permissive, and whatever you do, do not copy the scanner’s ai-input=no example. That line asks the models to exclude you. Set it to yes or leave it absent.

Then spend the rest of the hour in Bing Webmaster Tools reading Citation Share on your commercial-intent queries. That number is the closest thing on this list to revenue. Watch it move period over period, not day to day.

Where Lmo7 comes in depends on how much of this you want to run yourself. If you have the internal capacity and just need the data and the read on it, DaaS is the entry point, direct data access plus the upskilling to interpret it, from £250 plus VAT a month. If you want us to act on both sides, the readiness fixes and the authority and content work that moves Citation Share, that is the Challenger Agentic Stack, with tracking and content optimisation for AI search visibility as the core module. And if you are running a portfolio and need Citation Share and Share-of-Model tracked across several brands with the stakeholder alignment to act on it, that is Enterprise.

The one line I would leave you with: readiness is easy to measure and easy to over-invest in, because a scanner gives you a satisfying list to tick off. Visibility is harder to move and now, finally, free to watch in one engine. Put your hour where the revenue is.


Stephen Honight is the founder of Lmo7, an AI-native agency helping consumer brands win in AI-powered discovery and agentic commerce. Lmo7 works with brands including Trip Drinks, Veloforte, Brown-Forman, Haleon, Pelotan and Symprove across Amazon, D2C and AI search.

Explore More

AI Search Optimisation Services | LLM Visibility Framework | Free AI Search Audit | News & PR | Alexa Shopping Radar

Related Articles