Checklists
First Week Checklist
Use this checklist during the first week of an engagement to build a fact base quickly. The goal is enough evidence to identify risk and plan next steps, not perfect documentation.
Access and context
- Confirm engagement sponsor and day-to-day owner.
- Confirm communication channels and meeting cadence.
- Get access to source control, delivery systems, cloud accounts, and observability tools.
- Identify restricted systems and data handling rules.
- Gather existing architecture, onboarding, and incident documents.
Inventory
- List critical applications and business workflows.
- List repositories, pipelines, artifacts, and deployment targets.
- List runtime platforms, environments, accounts, and regions.
- List databases, queues, storage, and third-party integrations.
- Identify owners for every critical system.
Risk discovery
- Review recent incidents and failed deployments.
- Identify manual production changes.
- Check rollback and restore paths.
- Check secrets, privileged access, and break-glass process.
- Check monitoring coverage for critical services.
- Identify compliance or customer deadlines.
Outputs
By the end of week one, produce:
- Current-state summary.
- Initial service inventory.
- Top risk themes.
- Evidence gaps and follow-up interviews.
- First draft of the ranked backlog.