For deciding what comes next
Open Entry.
See where you stand. Decide what comes next.
The smallest engagement we run. Before you commit to building something new, rebuilding something old, or leaving something alone, there's a cheaper question to answer first: where are we, actually? Open Entry is that question, taken seriously — fixed length, fixed price, and an output you can act on.
It comes in two formats. The difference is where the uncertainty sits.
When the answer is hidden in your systems, we go read them. That's the Audit. When the answer is split across the people in your company, we get them in a room and extract it. That's the Workshop.
The Audit.
Somewhere in your company, a system runs the business. It works — mostly. But the person who built it has left, or the agency has moved on, or the documentation stops in 2019. Nobody dares touch it, and every decision that depends on it is made a little bit blind.
Or the opposite: your team ships faster than ever, with AI in the loop, and you have less visibility than ever into what's actually being produced. More code, more speed, and no way for you — the owner — to judge whether it's sound.
The Audit answers the questions that matter, in language you can read:
- Whether it's sound — the health of the code, the security posture, the state of updates and known vulnerabilities.
- Whether you can see what you're getting — how work is delivered, tested, and documented today, and whether you could verify any of it.
- Who really controls it — dependencies, vendors, licences, where your data lives and under whose law.
- What happens if a key person leaves — knowledge concentration, bus factor, succession risk.
- Whether it can evolve — what a new feature costs today, what it should cost, and where the friction comes from.
- What it costs to run — infrastructure and licence spend, measured against what the system actually needs.
Two weeks, with read-only access. Nothing changes in your systems while we're there. If we find something serious — an exposure, a ticking licence, a live risk — you hear about it the day we find it, not in the report.
You receive a report written for the owner, not for another engineer: a benchmark against modern practice and a prioritised path — what to fix now, what to plan, what to leave alone. Every item is marked with who can do it: your team, any competent partner, or us. We close with a half-day workshop where we walk you and your team through it and answer the hard questions.
The report is yours. Share it with your board, your buyer, your bank, or another supplier. It stands on its own.
The sovereignty variant. The same audit can be pointed at one question: where does your data actually run, what leaves your control, under whose law, and what it would take to bring it home. Same format, same fixed price, focused scope. Our position on sovereignty →
The Workshop.
Sometimes the system isn't the problem — the direction is. You know something needs to happen, but the knowledge is scattered: part of it in your head, part in your team's, part in constraints nobody has written down.
The Workshop is two days that end that state. A half-day of preparation, where we learn your context before walking in. A full day in the room with the people who own the problem. And a half-day of synthesis afterwards — because a good workshop produces more ideas than decisions, and the filtering and ordering is part of the work, not something we leave you to do alone.
What you leave with is buildable by design: a scoped backlog, a decision record, an architecture sketch — whatever the problem calls for. Never a deck.
Which format — and in which order.
There's no fixed sequence. Some clients start with an Audit and follow with a Workshop to decide what to do about the findings. Others start with a Workshop and commission an Audit when it becomes clear that nobody can answer what the current system will bear. Sometimes one is enough on its own.
The scoping call settles it. Tell us what's unclear, and we'll tell you which format answers it — or that neither does, and what would.
What comes after.
Open Entry is designed to end. The report or the backlog is yours, and many recommendations will read "your team can do this" — honestly marked, because our reputation depends on that being true.
If continuing together makes sense, the findings map directly onto the other engagements: a defined build is Open Build, ongoing work is Open Studio, embedded leadership is Open Lead. Part of the Open Entry fee is credited toward a longer engagement — but the output is written to stand on its own either way.
Good fit and not a good fit.
Works well when
- A system runs your business and the person who built it is gone.
- You're inheriting software — an acquisition, an agency handover, a departing CTO.
- You're about to invest — a rebuild, a scale-up, a fundraise — and want to know what breaks first.
- Your board or investors need technical clarity in language they can actually read.
- You know something must be built, but the direction lives in five people's heads and no document.
- A supplier tells you everything is fine, and you'd like a second pair of eyes.
Probably not the right fit if
- You need a certified penetration test or a compliance attestation — we'll tell you if you do, and point you to the right people.
- You want a rubber stamp for a decision that's already been made.
- You're looking for a free audit — a free audit is a pitch in disguise, and we'd rather sell you two honest weeks.
Questions people ask us.
Will the report just recommend hiring you?
Each recommendation is marked honestly, and many will read "any competent team can do this." The credit toward further work exists, but the report is written to stand on its own. Our reputation depends on that being true.
The original developer is gone and there's no documentation.
That's the classic case, not the exception. We need access to the code and the infrastructure; we reconstruct the rest by reading. The documentation is something you'll have after the audit.
Is the Audit a security audit?
It includes a security posture review — versions, exposure, practices, known vulnerabilities. It is not a penetration test. If your situation calls for one, the report will say so explicitly.
Why a fixed price instead of days?
Because you're buying findings and judgment, not hours. You pay for the conclusion, at a price known before we start.
What about confidentiality?
An NDA is standard. Nothing we find is ever published, referenced, or reused without your written approval.
Investment.
Open Entry is fixed-price, invoiced at start. The Audit and the Workshop each have their own fixed price, confirmed after a scoping call and announced before we begin — and it doesn't move. No hour counter, no surprises on the invoice.
Ask us for the offer document and you'll have the numbers the same day.
How to start.
One call: what runs your business, what's unclear, who has access. Within 48 hours you have a fixed quote and a start date.
Two weeks — or two days — later, you know exactly where you stand, and what to do about it.
Let's talkLean builders. We deliver.