What, precisely, is being acquired: an evidence-based register of customization debt, key-person exposure, vendor lock-in, data quality, and license posture. Every severity is measured, every figure traces to a reproducible query, every judgment call is disclosed — and the full register has been stress-tested by an independent cross-model adversarial review, with all verdicts and dispositions published in Appendix D.
The target operates a mature, single-currency (USD) NetSuite OneWorld production instance supporting full order-to-cash and procure-to-pay cycles, light manufacturing, and multi-location inventory across 15 locations. Transaction volume is modest (≈7,900 lifetime transactions) but the customization surface is not: 1,169 scripts, 438 custom record types, 151 custom lists, and 1,203 released-or-scheduled script deployments (with a further 626 deployed-not-scheduled that remain invocable).E1 E3
Second-edition comparison: 1 Critical · 5 High · 2 Medium · 3 Low. The High-band count fell because independent review found two risks over-scored and one scored on invalid evidence; one new Medium risk was added. Amendment log in Appendix D.
| Dimension | Measured state | Diligence note |
|---|---|---|
| Entity structure | 4 subsidiaries (1 elimination), single currency USD | No multi-currency complexity; consolidation integrity unassessed (U1) |
| Master data | 274 customers · 94 vendors · 195 contacts · 338 itemsE5 E7 E8 E9 | Small master files; item count fell 374→338 during diligence — see R12 |
| Transactions | ≈7.9K lifetime · 2,349 posting in FY2026 YTDE12 | Full O2C + P2P active; light mfg (24 work orders) |
| Scripts | 1,169 total → 459 local (39%) / 710 bundleE1 E2 | 1,203 released/scheduled; 626 deployed-not-scheduled remain invocable; 73 disabledE3 |
| Workflows | 17 total · 10 releasedE4 | Small estate, primarily bundle-sourced; ownership not assessed (U4) |
| Users & roles | 21 provisioned full users of 30 active employees · 109 roles (76 custom)E14 E15 | ≈21 seats; 3.6 custom roles per provisioned user; SoD unassessed (U3) |
| Integration surface | 183 RESTlets · 3 named OAuth apps · 5 web-service rolesE16 E17 | TBA token callers invisible to this method — seller must produce inventory (R7, U2) |
Severity = likelihood × impact, each scored 1–5 against the anchor definitions in Section 8. Scores marked amended were revised following independent review (Appendix D). Blind spots are deliberately not scored — they appear as Unassessed Areas in §7.
| ID | Risk | Evidence | L | I | Sev | Band |
|---|---|---|---|---|---|---|
| R1 | Plain-text credential storage — CUSTENTITY_PS_PASSWORD holds live vendor-portal passwords on vendor records, readable by any role with vendor access. First flagged 2026-08-05; still present. (Reviewer noted L5×I5=25 is arguable since the exposure is already extant; L4 retained reading likelihood as probability-of-breach — band is Critical either way.) | S-2 · A5 · D:C1 | 4 | 5 | 20 | Critical |
| R2 | Development bus-factor — effectively 2–3 active individuals maintain the entire bespoke codebase (32 of 459 local scripts attributable to active staff; 87.8% carry a system identity that the owner field cannot attribute; 81 scripts owned by 4 departed employees; 5 orphaned). Amended per review: owner-field opacity ≠ authorship lost — SDF sources/version history may exist but are unverified in this account. | E1 E2 · A1 A5 A6 · D:C2 | 4 | 3 | 12 | High was 16 |
| R3 | Financial-dimension gaps — 30.5% of FY2026 posting transactions carry lines with no department; 13.5% no location; 90.8% of items have no class. Caveat added per review: the department segment may be deliberately unused by policy — confirm with seller before treating the 30.5% as defect rather than design. | E9 E12 · D:C3 | 5 | 3 | 15 | High |
| R4 | SuiteApp lock-in — 847 customization objects (52.7%) belong to installed bundles; SuiteTax, Fixed Assets, Ship Central, and Manufacturing Mobile are structurally core (object count is a proxy — runtime criticality inferred, per review note) | E18 · A1 · D:C4 | 3 | 4 | 12 | High |
| R6 | Customer master gaps — 79.9% of customers lack payment terms; 75.9% lack a sales rep. (Terms may default at transaction time from customer category — master-data finding stands; operational impact may be lower.) | E5 · D:C6 | 4 | 3 | 12 | High |
| R7 | Unenumerated integration surface — 183 RESTlets constitute a large custom API; token-based callers are invisible to the login-audit method used here. Reworded per review: this is a diligence gap requiring seller disclosure, not a measured defect — see U2 for the escalation. | E16 E17 · A8 · D:C7 | 3 | 3 | 9 | Medium |
| R12 | Item-master shrinkage (new — added on reviewer finding) — item count fell 374→338 (−9.6%) between 2026-08-03 and 08-18, unexplained. Deletions, inactivations, or re-migration during a diligence window is a data-integrity signal requiring root cause from the seller. | E9 · S-2 · App C · D:M1 | 3 | 3 | 9 | Medium |
| R9 | Role sprawl — 76 custom roles serving 21 provisioned users (3.6 : 1); some roles may be legacy/unassigned, slightly overstating active sprawl | E14 E15 · A9 · D:C9 | 3 | 2 | 6 | Low |
| R10 | Journal-entry profile (reworded) — 53 of 88 lifetime JEs are dated 2026 YTD. Per review, this pattern is equally consistent with a young/recently-migrated instance as with acceleration; the causal claim is withdrawn. Confirm go-live date and JE approval policy with the seller's controller. | E13 · D:C10 | 2 | 3 | 6 | Low |
| R5 | AI access governance (amended 12→4) — AI OAuth clients (Claude AI, ChatGPT) have active access. The former "99.8% of traffic" framing was scored on data contaminated by this assessment's own tooling, and "no governance policy" was an absence-of-evidence inference — both corrected per review.残 remaining risk: unverified governance of standing AI access. Seller Q&A item. | E16 · A7 · D:C5 | 2 | 2 | 4 | Low was 12 |
| R8 | Residual custom footprint (amended 9→4) — 577 scripts / 183 record types unmatched to known bundles is largely the target's own normal customization, not inherently unmanaged (per review). Residual concern: the genuinely orphaned subset — 626 deployed-not-scheduled + 73 disabled deployments — is hidden-dependency cleanup for phase two. | E2 E3 E18 · A1 · D:C8 | 2 | 2 | 4 | Low was 9 |
| R11 | Vendor master decay — 43.6% of vendors lack email; 19.1% inactive. Read together with R1: the vendor master hosts both the decay and the credential exposure — treat holistically in remediation. | E7 · D:C11 | 2 | 2 | 4 | Low |
Only nine distinct owner identities exist across all 1,169 scripts.E1 The finding here is a bus-factor, stated precisely (and amended after independent review): the owner metadata cannot attribute 87.8% of bespoke code, and of what it can attribute, nearly everything maintainable rests with two or three active individuals.
| Owner | Total scripts | Local | Status |
|---|---|---|---|
| System identity (id -5, account-provisioning admin) | 1,039 | 403 | Owner field silent |
| Ryan Rote (id 1252) | 70 | 7 | Inactive · no access |
| T. Dietrich (ids 158 + 3894 — apparent duplicate employee records, A6) | 43 | 32 | Active |
| Ray Gravinese (id 5) | 8 | 8 | Inactive · no access |
| E. Goyena (1221) · C. Bermundo (1249) | 3 | 3 | Inactive · no access |
| Jacob Bailey (3871) | 1 | 1 | Active |
| No owner recorded | 5 | 5 | Orphaned |
52.7% of the customization estate (847 of 1,607 objects) is owned by installed SuiteApps.E18 Four are structurally core — tax computation, fixed-asset depreciation, warehouse execution, shop-floor data capture. Object count is a proxy for runtime criticality (per review note), but tax and fixed assets are load-bearing by construction. Migration cost concentrates here.
| Signal | Measured | Implication for buyer |
|---|---|---|
| Provisioned full-access users | 21 of 30 active employees | ≈21 seats to novate or renegotiate; 70% provisioning ratio |
| Custom roles | 76 | Permission-review effort scales with roles; consolidation candidate; SoD unassessed (U3) |
| Premium SuiteApps in use | 4 structurally core | SuiteTax, FAM, Ship Central, Mfg Mobile — confirm SuiteApp licensing transfers |
| OneWorld + Advanced modules | Subsidiaries, Multi-Loc Inventory, Work Orders, Adv. Printing | Mid-tier-plus edition; reconcile to the license schedule (A9) |
| Named OAuth clients | 3 (2 AI, 1 SuiteTalk) | AI clients hold standing access — governance unverified (R5); TBA callers invisible (U2) |
Two composites are shown per the independent review's methodological challenge (D:C12): the unweighted mean of six domain scores (76.8) and a materiality-weighted alternative (72.7) that weights financially significant domains more heavily. Formulas and weights: Section 8, A3/A11. The unweighted design flatters the estate; both are disclosed.
The bifurcation thesis survives review unchallenged (D:C13 confirmed): operational data is excellent; analytical dimensions are materially incomplete.
| Metric | Evidence | n / N | Gap | Reading |
|---|---|---|---|---|
| Items missing class (worst field — flagged per D:C12) | E9 | 307 / 338 | 90.8% | High |
| Customers missing payment terms (worst field) | E5 | 219 / 274 | 79.9% | High |
| Customers missing sales rep | E5 | 208 / 274 | 75.9% | High |
| Vendors missing email | E7 | 41 / 94 | 43.6% | Medium |
| FY2026 posting txns with dept-less lines (see R3 caveat) | E12 | 717 / 2,349 | 30.5% | High |
| Items missing description | E9 | 96 / 338 | 28.4% | Medium |
| FY2026 posting txns with location-less lines | E12 | 317 / 2,349 | 13.5% | Medium |
| Open POs > 90 days | E11 | 3 / 35 | 8.6% | Medium |
| Open SOs > 90 days | E10 | 1 / 57 | 1.8% | Strong |
| Customers missing email | E5 | 3 / 274 | 1.1% | Strong |
| Duplicate active customer names | E6 | 0 / 274 | 0.0% | Strong |
| Contacts missing email | E8 | 0 / 195 | 0.0% | Strong |
| Priority | Action | Addresses | Timing | Est. effort |
|---|---|---|---|---|
| 1 | Rotate all credentials stored in CUSTENTITY_PS_PASSWORD; migrate to a secrets store (or NetSuite API Secrets); purge field history | R1 | Pre-close | 1–2 days + vendor coordination |
| 2 | Require seller to produce the complete integration inventory — Setup > Integrations records, all active TBA tokens with their scopes and callers, and RESTlet caller mapping. This is the largest diligence blind spot (U2) and cannot be closed from outside. | R7, R5, U2 | Pre-close | Seller info request + 2–3 days review |
| 3 | Contractually require a script handover inventory (purpose, entry points, dependencies) for the 403 system-attributed local scripts, plus production of any external SDF repositories / source control; include key-developer transition services | R2, R8 | Pre-close / SPA | 2–4 weeks seller-side; SPA clause buyer-side |
| 4 | Root-cause the item-master shrinkage (374→338 in 15 days): system notes on deleted/inactivated items, or seller explanation. Re-measure at signing. | R12 | Q&A phase | Half-day + seller response |
| 5 | Confirm SuiteApp license transferability (SuiteTax, FAM, Ship Central, Mfg Mobile) and seat count (≈21) against the NetSuite contract and change-of-control clauses | R4, R9 | Pre-close | Contract review; NetSuite AM query |
| 6 | Obtain consolidation-integrity evidence: intercompany balance reconciliation, elimination JE review for the xElim subsidiary, consolidation configuration walkthrough (U1) | U1 | Financial DD | Route to financial diligence team |
| 7 | Remediate customer terms/rep assignment and item classification; confirm whether department is deliberately unused (R3 caveat) before enforcing dimensions on posting transactions | R3, R6, R11 | Close + 90d | 3–5 days data work + config |
| 8 | Seller Q&A: go-live date and JE approval policy (R10); AI-client access scope and governance policy (R5); ownership of Org Browser / ATB / RAC script families | R10, R5, R2 | Q&A phase | Three Q&A items |
Per the independent review, blind spots must not be converted into scored findings. These areas could not be assessed by this method and require the listed follow-up. Absence from the register is not evidence of absence of risk.
| ID | Area | Why unassessed | Required follow-up |
|---|---|---|---|
| U1 | OneWorld consolidation & intercompany integrity (xElim subsidiary correctness, elimination JEs) | Financial-integrity testing is outside this technical assessment's scope | Financial DD team: intercompany reconciliation + elimination review (Action 6) |
| U2 | TBA-token integration callers | integration record not exposed to SuiteQL; token callers absent from login-audit OAuth names | Seller-produced inventory (Action 2) |
| U3 | Segregation of duties / privileged access (admin-role count, web-service role scopes) | Not analyzed in this pass despite available role data — noted by reviewer | Feasible follow-up query set; recommend permissions-audit workstream |
| U4 | Saved-search (939) and workflow (17) ownership & dependency | Collected but not risk-assessed; same authorship-continuity concern as scripts | Phase-two scope alongside the code review |
Severities are the product of two 1–5 scores assigned against the anchors below, applied to measured evidence — and, in this edition, stress-tested by independent review with all disagreements published (Appendix D). Reasonable professionals may re-score; the inputs are all in Appendix B.
| Score | Anchor |
|---|---|
| 5 | Already manifesting — the condition is active in current-period data |
| 4 | Probable — standing condition with routine trigger paths (e.g., any staff departure, any audit) |
| 3 | Plausible — requires a common but not inevitable event (integration change, re-platforming decision) |
| 2 | Unlikely — requires an uncommon trigger |
| 1 | Remote |
| Score | Anchor |
|---|---|
| 5 | Security/legal exposure or operational stoppage; potential deal-term consequence |
| 4 | Material integration/transition cost or loss of critical institutional capability |
| 3 | Degraded management reporting or meaningful remediation project |
| 2 | Contained inefficiency; absorbed by BAU administration |
| 1 | Cosmetic |
Severity = L × I. Critical ≥ 17 · High 12–16 · Medium 7–11 · Low ≤ 6.
| ID | Assumption | Basis / risk if wrong |
|---|---|---|
| A1 | Bundle attribution by script-ID prefix. "Bundle-owned" = script ID matches one of 16 known prefixes: customscript_fam, %ncfar%, _ste_, _str_, _2663_, _9572_, _9997_, _15529_, atlas, packship/shipcentral, mfgmob, b360, cash360, item360, customscript_sc, customscript_ns. Used because this instance's customsegment.frombundle and related provenance fields are empty/unreliable (verified prior survey). | Mis-attribution possible both ways; concentration and bundle-share findings robust to modest reclassification. |
| A2 | Severity model is likelihood × impact on the Section 8 anchors, assigned by the assessor against cited evidence — then independently reviewed (Appendix D). | Analytical judgment; re-scoreable from Appendix B. Review-driven rescores applied to R2, R5, R8. |
| A3 | DQ score formula = 100 − mean gap per domain; unweighted composite across 6 domains. | Reviewer found the unweighted design flatters the estate; weighted alternative added (A11). |
| A4 | Open-order status codes: SO open = status ∉ {G, C, H}; PO open = status ∉ {G, H, C}. "Stale" = trandate before 2026-05-20. | NS standard letter codes; verified against this account's data shape. |
| A5 | Script owner field ≈ authorship proxy — known-weak. NS assigns owner at creation; SDF deploys and bundle installs land under provisioning identities. Per review: owner-field silence does not prove authorship is lost; external SDF sources/version history may exist (unverified here). | R2 reframed accordingly — the finding is bus-factor plus unverified mitigations, not "authorship destroyed." |
| A6 | "Tim Dietrich" (id 158) and "Timothy Dietrich" (id 3894) assumed the same individual holding two employee records. | Name-based inference — verify with HR. Reviewer note: even unmerged, top-1 concentration is 87.8%. |
| A7 | The AI-login data is contaminated by the diligence tooling itself. This assessment runs through an AI OAuth client; a substantial share of the 5,926 Claude AI events is self-generated. | Per review (D:C5), the former traffic-share metric was withdrawn as evidence; R5 rescored to Low and reframed as an unverified-governance question. |
| A8 | External-caller inventory is a lower bound. The integration record is not exposed to SuiteQL here; TBA-token callers are invisible to this method. | Escalated to U2 + Action 2 (seller must produce the inventory) rather than scored as a measured finding. |
| A9 | License tier inferred from enabled features, not from the commercial contract (not available to this assessment). | Reconcile against the actual license schedule during contract review. |
| A10 | Denominators are point-in-time. Item count 338 live vs ≈374 on 08-03; customer 274 vs 273. Gap percentages use same-query denominators. | Per review (D:C15), the item drift is escalated to scored risk R12 — disclosure alone was insufficient. |
| A11 | Materiality weights for the alternative composite (Customer 25%, Txn dims 25%, Item 20%, Open-order 15%, Vendor 10%, Contacts 5%) are the assessor's judgment of financial-reporting materiality. | Different weights shift the composite several points; both composites and all inputs are disclosed so any weighting can be recomputed. |
Canonical, re-runnable forms of the evidence queries, rendered to this account's house SuiteQL conventions. Execute in the SuiteQL Query Tool under an administrator role. Results shown as measured 2026-08-18; live re-runs will drift with normal activity. This account's SuiteQL does not support REGEXP_LIKE — prefix matching uses LIKE chains throughout. All arithmetic derived from these results was verified by independent review (Appendix D).
SELECT s.owner, e.entityid AS owner_name, e.isinactive AS owner_inactive, COUNT(*) AS script_count FROM script s LEFT JOIN employee e ON e.id = s.owner GROUP BY s.owner, e.entityid, e.isinactive ORDER BY script_count DESC
SELECT s.owner, e.entityid AS owner_name, COUNT(*) AS local_scripts FROM script s LEFT JOIN employee e ON e.id = s.owner WHERE LOWER(s.scriptid) NOT LIKE 'customscript_fam%' AND LOWER(s.scriptid) NOT LIKE '%ncfar%' AND LOWER(s.scriptid) NOT LIKE '%_ste_%' -- ... repeat NOT LIKE for all 16 bundle prefixes listed in A1 GROUP BY s.owner, e.entityid ORDER BY local_scripts DESC
SELECT sd.isdeployed, sd.status, COUNT(*) AS deployments FROM scriptdeployment sd GROUP BY sd.isdeployed, sd.status ORDER BY deployments DESC
SELECT w.releasestatus, COUNT(*) AS workflows FROM workflow w GROUP BY w.releasestatus ORDER BY workflows DESC
SELECT COUNT(*) AS total_customers, SUM(CASE WHEN c.email IS NULL THEN 1 ELSE 0 END) AS missing_email, SUM(CASE WHEN c.terms IS NULL THEN 1 ELSE 0 END) AS missing_terms, SUM(CASE WHEN c.salesrep IS NULL THEN 1 ELSE 0 END) AS missing_salesrep, SUM(CASE WHEN c.defaultbillingaddress IS NULL THEN 1 ELSE 0 END) AS missing_bill_addr, SUM(CASE WHEN c.isinactive = 'T' THEN 1 ELSE 0 END) AS inactive_customers FROM customer c
SELECT COUNT(*) AS duplicate_names FROM ( SELECT c.companyname FROM customer c WHERE c.isinactive = 'F' AND c.companyname IS NOT NULL GROUP BY c.companyname HAVING COUNT(*) > 1 )
SELECT COUNT(*) AS total_vendors, SUM(CASE WHEN v.email IS NULL THEN 1 ELSE 0 END) AS missing_email, SUM(CASE WHEN v.isinactive = 'T' THEN 1 ELSE 0 END) AS inactive_vendors FROM vendor v
SELECT COUNT(*) AS total_contacts, SUM(CASE WHEN ct.email IS NULL THEN 1 ELSE 0 END) AS missing_email, SUM(CASE WHEN ct.company IS NULL THEN 1 ELSE 0 END) AS unattached FROM contact ct
SELECT COUNT(*) AS total_items, SUM(CASE WHEN i.class IS NULL THEN 1 ELSE 0 END) AS missing_class, SUM(CASE WHEN i.description IS NULL THEN 1 ELSE 0 END) AS missing_description, SUM(CASE WHEN i.isinactive = 'T' THEN 1 ELSE 0 END) AS inactive_items FROM item i
SELECT COUNT(*) AS open_sales_orders, SUM(CASE WHEN t.trandate < TO_DATE('2026-05-20','YYYY-MM-DD') THEN 1 ELSE 0 END) AS open_over_90_days FROM transaction t WHERE t.type = 'SalesOrd' AND t.status NOT IN ('G', 'C', 'H') -- G=Billed, C=Cancelled, H=Closed
SELECT COUNT(*) AS open_purchase_orders, SUM(CASE WHEN t.trandate < TO_DATE('2026-05-20','YYYY-MM-DD') THEN 1 ELSE 0 END) AS open_over_90_days FROM transaction t WHERE t.type = 'PurchOrd' AND t.status NOT IN ('G', 'H', 'C')
SELECT COUNT(DISTINCT t.id) AS txns_with_deptless_lines FROM transaction t JOIN transactionline tl ON tl.transaction = t.id WHERE t.posting = 'T' AND t.trandate >= TO_DATE('2026-01-01','YYYY-MM-DD') AND tl.mainline = 'F' AND tl.department IS NULL -- second run: tl.location IS NULL
SELECT COUNT(*) AS total_journals, SUM(CASE WHEN t.trandate >= TO_DATE('2026-01-01','YYYY-MM-DD') THEN 1 ELSE 0 END) AS journals_2026 FROM transaction t WHERE t.type = 'Journal'
SELECT COUNT(*) AS active_employees, SUM(CASE WHEN e.giveaccess = 'T' THEN 1 ELSE 0 END) AS provisioned_users FROM employee e WHERE e.isinactive = 'F'
SELECT CASE WHEN r.id >= 1000 THEN 'CUSTOM' ELSE 'STANDARD' END AS role_class, COUNT(*) AS role_count FROM role r GROUP BY CASE WHEN r.id >= 1000 THEN 'CUSTOM' ELSE 'STANDARD' END
SELECT la.oauthappname, COUNT(*) AS login_events FROM LoginAudit la WHERE la.oauthappname IS NOT NULL GROUP BY la.oauthappname ORDER BY login_events DESC
SELECT COUNT(*) AS restlet_count FROM script s WHERE s.scripttype = 'RESTLET'
-- Example: Fixed Assets family. Repeat with each family's prefixes -- against BOTH script and customrecordtype tables. SELECT COUNT(*) AS fam_scripts FROM script s WHERE LOWER(s.scriptid) LIKE 'customscript_fam%' OR LOWER(s.scriptid) LIKE '%ncfar%'
SELECT COUNT(*) AS saved_searches FROM savedsearch
| ID | Source | Date | Role in this report |
|---|---|---|---|
| S-1 | Live SuiteQL measurement session — three parallel read-only research passes (ownership; data quality; lock-in & license), executed under administrator session against production | 2026-08-18 | Primary evidence — all E1–E19 figures |
| S-2 | Prior verified account survey (account facts, feature set, org dimensions, custom-record census, local-customization survey incl. the CUSTENTITY_PS_PASSWORD finding) | 2026-08-03 / 08-05 | Baseline context; R1 origin; bundle-prefix list (A1) |
| S-3 | House SuiteQL style guide (account-specific query conventions) | current | Query rendering standard for Appendix B |
| S-4 | Severity computation worksheet (Section 8 formulas applied to E1–E19) | 2026-08-18 | All L×I scores and DQ domain scores; deterministic given inputs |
| S-5 | Independent cross-model adversarial review — 16 claims audited, arithmetic verification, missed-risk sweep (full packet & verdicts: Appendix D) | 2026-08-18 | Third-edition amendments: R2/R5/R8 rescores, R12 addition, R10/C14 rewording, dual composite, Unassessed Areas |
| Figure | Survey (08-03) | Live (08-18) | Disposition |
|---|---|---|---|
| Items | ≈374 | 338 | −36 (−9.6%) — escalated to scored risk R12 per independent review: unexplained master-data volatility during a diligence window requires root cause, not just disclosure. Seller Q&A (Action 4). |
| Customers | 273 | 274 | +1 — normal growth; immaterial. |
| Scripts | ≈1,150 | 1,169 | Delta not evidentially usable — baseline explicitly approximate (per review, D:C14). Former "active development" claim withdrawn. Change-freeze recommendation retained as standard practice only. |
| Custom record types | 437 | 438 | +1; immaterial. |
All figures were measured directly against the production instance on August 18, 2026, via read-only SuiteQL under an administrator session, supplemented by prior verified survey work (S-2), then independently reviewed (S-5). Severity scores are likelihood × impact per Section 8. Limitations: (i) bundle attribution is prefix-based (A1); (ii) the integration record is not exposed to SuiteQL here — external-caller inventory is a lower bound (A8, U2); (iii) script ownership reflects the owner field, a known-weak authorship proxy (A5); (iv) no code-level review of the 577 residual scripts — phase-two workstream; (v) the AI-login data includes this assessment's own tooling traffic (A7); (vi) license conclusions are feature-inferred (A9); (vii) consolidation integrity, SoD, and saved-search/workflow ownership were not assessed (U1, U3, U4).
On 2026-08-18, the complete evidence base (all 19 measurements), the computed metrics with formulas, and the 16 claims of the second-edition register — stated neutrally, with the assessor's recommendations withheld — were submitted to an independent reviewing model operating under an adversarial-review charter: verify all arithmetic; flag claims where evidence does not support the language; flag over/under-scored risks with proposed rescores; identify material risks the register missed. The reviewer's verdicts are reproduced below verbatim in substance, followed by the assessor's disposition of each. Where a disposition is "accepted," the body of this report has been amended accordingly; nothing was silently changed — the amendment log at the end of this appendix is complete.
| Claim | Verdict | Reviewer's reasoning (substance, verbatim where quoted) | Disposition |
|---|---|---|---|
| C1 R1 credentials (20 Critical) | Confirmed | "Plain-text stored credentials are a live security/legal exposure (I5 defensible). L4 slightly conservative … this is already-manifesting (L5). Rescore L5×I5=25 arguably warranted, but L4 is defensible if likelihood is read as likelihood of breach. Either band is Critical." | Accepted. Score retained at 20 with the likelihood-of-breach reading documented in the register row. |
| C2 R2 key-person (was 16) | Challenged | "'Authorship untraceable' is overstated. Owner -5 is the system/provisioning identity — scripts deployed via SDF/bundle install commonly land under a provisioning identity; that is not the same as 'authorship unknown.' … The real risk is key-person/bus-factor on the 32 local scripts under the Dietrich identity, not the -5 concentration." Proposed L3×I3=9. | Partially accepted — rescored 16→12 (L4×I3). Framing amended to bus-factor; impact reduced accepting that owner-field silence ≠ authorship lost. Likelihood held at 4 over the reviewer's 3: the SDF/version-history mitigations the reviewer cites are unverified in this account, and 4 departed owners + 5 orphans are measured, standing conditions. |
| C3 R3 dimensions (15) | Challenged | "Department may be intentionally unused if the org segments by class/location instead … the department finding needs the alternative explanation (segment not in use by design) tested before calling it a defect. Keep High band, add caveat." | Accepted. Score retained; design-vs-defect caveat added to the register row and Action 7. |
| C4 R4 lock-in (12) | Confirmed | "Bundle dependency is a genuine transition-cost/lock-in risk … object count ≠ runtime criticality, but tax/FA/warehouse are structurally core." | Accepted. Proxy limitation noted in §5. |
| C5 R5 AI egress (was 12) | Error | "The 99.8% figure is contaminated by the diligence tooling's own traffic … Using a self-generated metric as evidence of the target's AI exposure is circular. 'No governance policy evidenced' is absence-of-evidence used as evidence … Downgrade to informational or L2×I2=4. The ERROR is the reasoning, not the arithmetic." | Accepted in full — rescored 12→4 Low. Reframed as unverified-governance seller Q&A item. Executive summary, matrix, and actions amended. |
| C6 R6 customer master (12) | Confirmed | "Missing terms and sales rep degrade AR automation and reporting … terms-null may default at transaction time — as a master-data-quality finding it stands." | Accepted. Default-at-transaction caveat added. |
| C7 R7 integrations (9) | Challenged | "This restates a tooling limitation as a risk … should be labeled as a diligence gap requiring the seller to produce the integration/token inventory, not as a measured finding. Reword; score acceptable." | Accepted. Reworded as diligence gap; escalated to Action 2 + U2; score retained. |
| C8 R8 unclassified debt (was 9) | Challenged | "'Unattributed' means 'unmatched to the 16 known bundle prefixes,' NOT 'authorship unknown' … expected and largely benign (it's the customer's own customization). Also '1,203 executing deployments' mislabels the metric [NOTSCHEDULED deployments remain invocable]." Proposed L2×I2=4. | Accepted — rescored 9→4 Low. Terminology corrected throughout (§2, §4); orphaned-deployment subset (626+73) routed to phase two. |
| C9 R9 roles (6) | Confirmed | "Genuine sprawl but low-impact … some roles may be legacy/unassigned — the ratio overstates active sprawl slightly." | Accepted. Caveat added. |
| C10 R10 JE trend (6) | Challenged | "88 JEs lifetime … implies this instance is young or JEs are rare; 60% being YTD is fully consistent with a recently-migrated/go-live instance, not 'volume acceleration.' Without a go-live date the acceleration narrative is unsupported." | Accepted. Causal claim struck; reworded as go-live-consistency question; band unchanged (Low). |
| C11 R11 vendors (4) | Confirmed | "Low severity appropriate." | Accepted. Cross-reference to R1 added per reviewer's missed-risk note 8. |
| C12 DQ composite 76.8 | Challenged | "The unweighted mean biases the composite upward and is structurally misleading … a catastrophic field (terms 79.9% null) is averaged against a trivial one (email 1.1% null), diluting severity … A materiality-weighted or worst-field-flagged design would produce a lower, more honest number." | Partially accepted. Unweighted composite retained for transparency; materiality-weighted composite (72.7, A11) added alongside it everywhere the score appears; §6 table re-sorted worst-field-first. |
| C13 Bifurcation thesis | Confirmed | "The strongest defensible synthesis in the packet." | Retained. |
| C14 Change-freeze basis | Error | "The prior count is explicitly approximate and item count dropped over the same window … the delta is within measurement noise. The change-freeze recommendation may be prudent generally, but this specific evidentiary basis is invalid." | Accepted in full. Claim struck from Appendix C; change-freeze retained as standard practice only, explicitly not a finding (§7 note). |
| C15 Item reconciliation handling | Challenged | "A 10% drop in item master in 15 days is itself a material finding (deletions? inactivations? re-migration?) that is dismissed rather than investigated. The reconciliation is disclosed, not explained." | Accepted. Escalated to new scored risk R12 (L3×I3=9 Medium) + Action 4. |
| C16 Overall score supportability | Challenged | "The register systematically converts tooling blind spots into findings (C5, C7, C2's -5 identity), and treats normal custom footprint (C8) as risk. Net effect: inflated High-band count." | Accepted in net. High band reduced 5→4; blind spots moved to the Unassessed Areas structure (§7); this appendix documents every change. |
| # | Reviewer finding | Disposition |
|---|---|---|
| M1 | "Item master shrinkage (374→338, −9.6% in 15 days) is a risk, not a footnote." | Accepted → new risk R12 (Medium) + Action 4. |
| M2 | "Elimination subsidiary / OneWorld consolidation integrity untested … a core M&A financial-integrity area entirely absent." | Accepted → U1 + Action 6, routed to financial DD. Deliberately not scored (scoring an untested area would repeat the absence-of-evidence error). |
| M3 | "Disabled/orphaned deployments (73 + 626 not-scheduled) never flagged — real cleanup and hidden-dependency risk." | Accepted → folded into amended R8 and the phase-two scope; §4 terminology corrected. |
| M4 | "Effectively the entire maintainable custom codebase depends on one or two active people. This bus-factor risk is stronger than the -5 concentration C2 leans on." | Accepted → R2 reframed around exactly this; §4 rewritten. |
| M5 | "TBA/token integration surface entirely unquantified … the single largest diligence blind spot; escalate to a seller information request." | Accepted → promoted to Action 2 (second-highest priority) + U2. |
| M6 | "No segregation-of-duties / privileged-access analysis despite having role and giveaccess data." | Accepted → U3. Feasible with available data; recommended as a dedicated permissions-audit workstream rather than a rushed addendum. |
| M7 | "Saved searches (939) and workflows (17) collected but never risk-assessed for ownership/dependency." | Accepted → U4 + phase-two scope. |
| M8 | "Vendor master is arguably the highest-risk object in the estate (R1 credentials + R11 decay) and isn't treated holistically." | Accepted → cross-references added to R1/R11; remediation Actions 1 and 7 treat the vendor master as one workstream. |
All four weakness classes have been remediated in this edition as documented above. No reviewer verdict was rejected outright; one (C2) was accepted in part with a documented, reasoned divergence on the likelihood score.
| # | Change | Driver |
|---|---|---|
| 1 | R2 rescored 16→12; reframed from "authorship untraceable" to development bus-factor; §4 rewritten | C2, M4 |
| 2 | R5 rescored 12→4; AI traffic-share metric withdrawn as evidence; reframed as unverified-governance Q&A item | C5 (Error) |
| 3 | R8 rescored 9→4; "unattributed = unmanaged" conflation corrected; "1,203 executing" terminology corrected (626 not-scheduled remain invocable) | C8, M3 |
| 4 | R12 added (item-master shrinkage, 9 Medium); Appendix C reconciliation row escalated | C15, M1 |
| 5 | R10 causal "acceleration" claim struck; reworded as go-live-consistency question | C10 |
| 6 | "+19 scripts → change-freeze" evidentiary claim withdrawn; change-freeze retained as standard practice only | C14 (Error) |
| 7 | Materiality-weighted composite (72.7) added alongside unweighted (76.8); §6 table re-sorted worst-field-first; A11 added | C12 |
| 8 | Unassessed Areas structure added (U1–U4: consolidation integrity, TBA tokens, SoD, saved-search/workflow ownership); blind spots no longer scored | C16, M2 M5 M6 M7 |
| 9 | R3 design-vs-defect caveat; R6 terms-default caveat; R9 legacy-roles caveat; R1/R11 vendor-master cross-reference; R4 object-count-proxy note | C3 C6 C9 M8 C4 |
| 10 | Actions reprioritized: seller integration-inventory request elevated to Priority 2; item-shrinkage root cause added as Priority 4; consolidation evidence added as Priority 6 | M5 M1 M2 |