Software nobody signed off
Internal tools, spreadsheets that behave like applications, scripts on somebody’s laptop, and apps made in Power Platform, Lovable or Replit. If the business relies on it, it goes on the list.
Consult · Software audit
The developer who wrote the order system has moved on, and since then the finance and operations teams have started building their own tools with Claude and Zapier. I find out what you have, what it costs, who owns it and what would hurt if it stopped. Then I help you fix or build what matters.
What a software audit covers
The audit starts with a list: every application, script, bot, automation and AI tool the business leans on. For each one I write down what it’s for, who uses it, who could fix it, what data it touches and what else stops if it fails, and I get a good part of that from sitting with the people who use each tool, because the code won’t tell you who depends on it. The risk turns up while the list is being written (a customer database opened by a key in a shared document, say).
Who owns the app your finance team built explains why the list gets long so quickly. In short, a tool no longer needs a budget, so it no longer needs anyone senior to agree to it.
I don’t treat AI-written code as the problem, and I write code with these tools every week myself. What I check is whether anything sits around it: a review before it ships, a test that would catch it breaking, keys kept out of the source, and a named person who answers when it fails.
I carry a P&L for my own company’s software, so the last part is commercial: some systems stay as they are, some merge because two departments built the same thing, and a few want rebuilding properly, and I can build those myself.
What I look at
Internal tools, spreadsheets that behave like applications, scripts on somebody’s laptop, and apps made in Power Platform, Lovable or Replit. If the business relies on it, it goes on the list.
Which models see company data, under whose account, and what an agent can do through its tools and keys without a person approving it.
Who can reach production, where the credentials live, and whether anyone who left in the last two years still has a way in.
For each system that matters, what happens if the person who built it leaves tomorrow: the source, the passwords, the backups, and whether anyone else has ever deployed it.
Where twenty sensible automations add up to one fragile system, and a renamed field in one tool breaks another three steps away.
Licences, model and API spend, and the hours that keep each system alive, set against what it does for the business.
Where it starts
All prices exclude VAT.
The audit is the diagnostic, pointed at what you already run. Building the list and ranking it is the triage, and the proof is a question settled on your own systems, such as whether anyone but its author can deploy the one the business depends on.
Questions
I look at access, keys and anything left exposed, at the depth a board needs to decide what to do next, and I don’t try to break in. Where something needs attacking properly, I’ll name the specialist to bring in. A leaver whose account still works, or a key sitting in a repository, needs no test to find.
No. AI is why the list got longer so quickly, and plenty of what I review was typed by hand. The audit covers whatever the business runs on, whoever wrote it.
It runs as The Leverage Diagnostic: two weeks, fixed, £7,500. All prices exclude VAT. One system on its own is a bounded review at £1,000 a day, with the days agreed before it starts.
You keep the list and the plan, and either can go to anyone. Where the plan says build, I can quote for it, and where it says somebody should own the technology from here on, that’s what Partner is for.
From Insights
Staff can build a working tool in an afternoon now. Eight questions that tell you whether anyone still knows what the business runs on.
Read itOther ways to work together
Build
Partner
Consult
Work with me
I reply within one working day to arrange a free 30-minute call.