Tutorial: Map a Company's Cyber-Market Exposure
Anchor a ledger subject to a company, record a sourced identifier and a supplier tie, then read the fused timeline
In this tutorial you will record what a public page says about a company, link one of its suppliers, and read the cyber and market events that reach the company through that supplier. It takes about ten minutes. You need a workspace with FININT, Cyber, or Explorer access and an owner, admin, or member role.
We will use a company from the shared catalog. Any organization or vendor works; the examples use Northwind Example Holdings and its supplier Contoso Example Logistics.
Open the company
Go to FININT → Markets → Companies and select the company. The company page shows its shared identity, your workspace's financial history, the Cyber-market exposure panel, and the Entity ledger panel.
Open a ledger subject
In Entity ledger, choose Open ledger subject. Y2 appends a subject line of class
organization and anchors it to the catalog company. The subject has no name yet: opening a row
is not a finding. Names and identifiers arrive as claims with evidence.
Record the company's domain with its source
In Record an identifier with its source, enter:
| Field | Value |
|---|---|
| Kind | Domain |
| Value | northwind.example |
| Public source URL | The company's home page |
| Method | Public web page |
| Excerpt | The sentence on the page that shows the domain |
| Verification | Self-asserted (the company's own page says so) |
| Confidence | 85 |
Choose Record claim. Y2 records three lines in one transaction: the domain designator, the
observation (source URL, retrieval time, excerpt, and its SHA-256), and a designated-by claim
that cites the observation. The domain now appears in the ledger with its verification badge.
Add a published name and make it the label
Record a second identifier of kind Published name from the same page. It appears as a
designation, but the subject still has no display label: a label is its own claim, never a guess.
Choose Use as label next to the name. Y2 records an analyst note that cites the page you used,
and a preferred-label claim graded analytic because its only support is that note.
Link the supplier
In Record a supply or ownership tie, search the shared catalog for the supplier, choose the
role Supplier of this company, and cite the page that names it, such as the company's annual
filing on a public registry. Y2 opens a ledger subject for the supplier if your workspace has none,
then records a supplies claim from the supplier to the company.
Read the exposure timeline
Return to the company. Cyber-market exposure now lists the supplier on the exposure path with
ledger · located, next to any suppliers the shared catalog already knows. CVEs that affect the
supplier, cyber signals about it, and market events about the company appear on one timeline.
When a market event followed a cyber event within seven days, it is listed under Market events
after cyber events. That list is timing on a shared path, not a claim of causation.
Do the same through the API
With a workspace-bound key that holds ledger:read and ledger:write:
# Open the subject, anchored to the catalog entity.
curl https://api.y2.dev/api/v2/ledger/subjects \
--header "Authorization: Bearer $Y2_API_KEY" \
--header "Idempotency-Key: open-northwind-1" \
--json '{"class":"organization","entityId":"ent_0123456789abcdef01234567"}'
# Record the observation, then the designator, then the claim that cites it.
curl https://api.y2.dev/api/v2/ledger/records \
--header "Authorization: Bearer $Y2_API_KEY" \
--json '{"kind":"observation","observation":{"method":"public-web-page","sourceGrade":"primary","sourceUrl":"https://northwind.example/","retrievedAt":"2026-06-01T11:45:00Z","excerpt":"Northwind Example Holdings — northwind.example","collector":"integration"}}'
curl https://api.y2.dev/api/v2/ledger/records \
--header "Authorization: Bearer $Y2_API_KEY" \
--json '{"kind":"designator","designator":{"kind":"published-name","value":"Northwind Example Holdings"}}'
curl https://api.y2.dev/api/v2/ledger/records \
--header "Authorization: Bearer $Y2_API_KEY" \
--json '{"kind":"claim","claim":{"predicate":"designated-by","from":"sbj_…","to":"dsg_…","confidence":80,"verification":"self-asserted","evidenceRefs":["obv_…"]}}'Then record the label as its own claim, which needs an analyst note that cites the page:
curl https://api.y2.dev/api/v2/ledger/records \
--header "Authorization: Bearer $Y2_API_KEY" \
--json '{"kind":"observation","observation":{"method":"analyst-note","sourceGrade":"analytic","excerpt":"Display the name the site prints.","collector":"integration","cites":["obv_…"]}}'
curl https://api.y2.dev/api/v2/ledger/records \
--header "Authorization: Bearer $Y2_API_KEY" \
--json '{"kind":"claim","claim":{"predicate":"preferred-label","from":"sbj_…","to":"dsg_…","confidence":60,"verification":"analytic","evidenceRefs":["obv_…note"]}}'Finally, read the fused view with a key that holds intel:explorer:
curl --get "https://api.y2.dev/api/v2/entities/ent_0123456789abcdef01234567/fusion" \
--header "Authorization: Bearer $Y2_API_KEY" \
--data-urlencode "windowDays=90"What you built
You now have a small, sealed record of what public pages say about a company and one of its suppliers, with each claim graded by its evidence. Fusion uses those ties to bring the supplier's cyber exposure onto the company's timeline, and every event on it links back to its source.
Next steps:
- Correct, supersede, or retract a claim when a page changes.
- Read the ledger at a point in time to see what you believed before a correction.
- Export STIX and verify the seal to share the claims.