Sample output from the Account Prenup prompt in the Sonar AI Prompt Library, run against a NetSuite test account. Every name and number here is test data. Back to the post · The library
Confidential · Buy-side Technical Due Diligence · Third Edition — Independently Reviewed

Account Prenup

NetSuite Instance Assessment — Account TD3016323

What, precisely, is being acquired: an evidence-based register of customization debt, key-person exposure, vendor lock-in, data quality, and license posture. Every severity is measured, every figure traces to a reproducible query, every judgment call is disclosed — and the full register has been stress-tested by an independent cross-model adversarial review, with all verdicts and dispositions published in Appendix D.

Assessment dateAugust 18, 2026
EnvironmentProduction · OneWorld · 4 subsidiaries
MethodLive SuiteQL introspection, read-only
Evidence19 queries · 11 assumptions
Risks registered12 (1 Critical · 4 High)
Independent review16 claims audited · 2 errors found & corrected
1Executive Summary 2The Asset — Instance Footprint 3Risk Matrix & Register 4Key-Person Exposure 5Lock-In & License Posture 6Data Quality Scorecard 7Actions & Unassessed Areas 8Scoring Model AAssumptions Register BEvidence & Queries CSources & Reconciliation DIndependent Review & Dispositions
Section 1

Executive Summary


The target operates a mature, single-currency (USD) NetSuite OneWorld production instance supporting full order-to-cash and procure-to-pay cycles, light manufacturing, and multi-location inventory across 15 locations. Transaction volume is modest (≈7,900 lifetime transactions) but the customization surface is not: 1,169 scripts, 438 custom record types, 151 custom lists, and 1,203 released-or-scheduled script deployments (with a further 626 deployed-not-scheduled that remain invocable).E1 E3

0/100
Data quality — unweighted (72.7 materiality-weighted, §8)
0%
Local scripts under a single owner identity
0%
Customization objects owned by installed bundles
0%
Item-master shrinkage in 15 days — unexplained (R12)
Principal Finding The instance is operable and structurally sound, but three conditions warrant pre-close remediation or purchase-price consideration: a plain-text credential field on vendor records (R1, Critical); a severe development bus-factor — effectively two or three active individuals maintain the entire bespoke codebase, with owner metadata unable to attribute 87.8% of it (R2, High); and financial-dimension gaps affecting 30.5% of current-year posting transactions (R3, High). A fourth condition emerged from independent review: the item master shrank 9.6% during the diligence window itself, unexplained (R12, Medium — escalate to seller Q&A).
Independent review. This edition's register was audited claim-by-claim by an independent cross-model adversarial reviewer. All arithmetic was confirmed. Two reasoning errors were found and corrected (the former AI-egress risk was scored on self-contaminated data; a change-freeze claim rested on measurement noise), three risks were re-scored, one new risk was added, and diligence blind spots were moved out of the scored register into §7's Unassessed Areas. Full verdicts and dispositions: Appendix D.

The verdict in one panel

Clean — take as-is
  • Zero duplicate active customer namesE6
  • Contacts 99.2% completeE8
  • Open-order backlog current: 4 of 92 open orders > 90 daysE10 E11
  • Single currency; no FX complexity
  • Clean elimination structure (1 dedicated sub)
Remediate — price it in
  • Plain-text vendor credentials (R1)
  • Dimension coding gaps: 30.5% dept-less FY26 postings (R3)
  • Customer terms/rep gaps ≈ 76–80% (R6)
  • Item classification 90.8% missing (R3)
  • Item-master shrinkage — investigate (R12)
Contract protection
  • Script handover inventory + transition services (R2)
  • SuiteApp license transferability ×4 (R4)
  • Seller-produced integration/token inventory (R7, U2)
  • Consolidation-integrity representations (U1)
  • ≈21 seats to novate (R9)

Severity distribution — 12 registered risks (post-review)

Critical (sev ≥ 17)
1
High (12–16)
4
Medium (7–11)
2
Low (≤ 6)
5

Second-edition comparison: 1 Critical · 5 High · 2 Medium · 3 Low. The High-band count fell because independent review found two risks over-scored and one scored on invalid evidence; one new Medium risk was added. Amendment log in Appendix D.

Account Prenup · TD3016323 · Confidential— 2 —
Section 2

The Asset — Instance Footprint


0
Script records
0
Custom record types
0
Saved searches
0
Custom roles
0
Workflows
DimensionMeasured stateDiligence note
Entity structure4 subsidiaries (1 elimination), single currency USDNo multi-currency complexity; consolidation integrity unassessed (U1)
Master data274 customers · 94 vendors · 195 contacts · 338 itemsE5 E7 E8 E9Small master files; item count fell 374→338 during diligence — see R12
Transactions≈7.9K lifetime · 2,349 posting in FY2026 YTDE12Full O2C + P2P active; light mfg (24 work orders)
Scripts1,169 total → 459 local (39%) / 710 bundleE1 E21,203 released/scheduled; 626 deployed-not-scheduled remain invocable; 73 disabledE3
Workflows17 total · 10 releasedE4Small estate, primarily bundle-sourced; ownership not assessed (U4)
Users & roles21 provisioned full users of 30 active employees · 109 roles (76 custom)E14 E15≈21 seats; 3.6 custom roles per provisioned user; SoD unassessed (U3)
Integration surface183 RESTlets · 3 named OAuth apps · 5 web-service rolesE16 E17TBA token callers invisible to this method — seller must produce inventory (R7, U2)
Assumption A1 applies throughout. "Local" scripts are those whose script IDs match none of the 16 known bundle prefixes (full list in Appendix A). Residual mis-attribution is possible in both directions; it does not alter the concentration finding materially. Note (post-review): "local/unattributed" means not matched to a known bundle — it does not by itself imply unmanaged or unowned code.
Account Prenup · TD3016323 · Confidential— 3 —
Section 3

Risk Matrix & Register

Severity = likelihood × impact, each scored 1–5 against the anchor definitions in Section 8. Scores marked amended were revised following independent review (Appendix D). Blind spots are deliberately not scored — they appear as Unassessed Areas in §7.

Likelihood →
R3
Dim. gaps
R2 R6
Bus-factor · Cust.
R1
Credentials
R9
Roles
R7 R12
Integr. · Items
R4
Lock-in
R5 R8 R11
AI · Debt · Vendors
R10
JE profile
1
2
3
4
5
Impact →

Severity ranking — all 12 risks (scale 0–25)

R1
20 · Critical — plain-text credentials
R3
15 · High — dimension gaps
R2
12 · High — dev bus-factor (amended 16→12)
R4
12 · High — SuiteApp lock-in
R6
12 · High — customer master gaps
R7
9 · Medium — unenumerated integrations
R12
9 · Medium — item-master shrinkage (new)
R9
6 · Low — role sprawl
R10
6 · Low — JE profile (reworded)
R5
4 · Low — AI access governance (amended 12→4)
R8
4 · Low — residual custom footprint (amended 9→4)
R11
4 · Low — vendor decay

Register — measured severities with evidence citations

IDRiskEvidenceLISevBand
R1Plain-text credential storage — CUSTENTITY_PS_PASSWORD holds live vendor-portal passwords on vendor records, readable by any role with vendor access. First flagged 2026-08-05; still present. (Reviewer noted L5×I5=25 is arguable since the exposure is already extant; L4 retained reading likelihood as probability-of-breach — band is Critical either way.)S-2 · A5 · D:C14520Critical
R2Development bus-factor — effectively 2–3 active individuals maintain the entire bespoke codebase (32 of 459 local scripts attributable to active staff; 87.8% carry a system identity that the owner field cannot attribute; 81 scripts owned by 4 departed employees; 5 orphaned). Amended per review: owner-field opacity ≠ authorship lost — SDF sources/version history may exist but are unverified in this account.E1 E2 · A1 A5 A6 · D:C24312High was 16
R3Financial-dimension gaps — 30.5% of FY2026 posting transactions carry lines with no department; 13.5% no location; 90.8% of items have no class. Caveat added per review: the department segment may be deliberately unused by policy — confirm with seller before treating the 30.5% as defect rather than design.E9 E12 · D:C35315High
R4SuiteApp lock-in — 847 customization objects (52.7%) belong to installed bundles; SuiteTax, Fixed Assets, Ship Central, and Manufacturing Mobile are structurally core (object count is a proxy — runtime criticality inferred, per review note)E18 · A1 · D:C43412High
R6Customer master gaps — 79.9% of customers lack payment terms; 75.9% lack a sales rep. (Terms may default at transaction time from customer category — master-data finding stands; operational impact may be lower.)E5 · D:C64312High
R7Unenumerated integration surface — 183 RESTlets constitute a large custom API; token-based callers are invisible to the login-audit method used here. Reworded per review: this is a diligence gap requiring seller disclosure, not a measured defect — see U2 for the escalation.E16 E17 · A8 · D:C7339Medium
R12Item-master shrinkage (new — added on reviewer finding) — item count fell 374→338 (−9.6%) between 2026-08-03 and 08-18, unexplained. Deletions, inactivations, or re-migration during a diligence window is a data-integrity signal requiring root cause from the seller.E9 · S-2 · App C · D:M1339Medium
R9Role sprawl — 76 custom roles serving 21 provisioned users (3.6 : 1); some roles may be legacy/unassigned, slightly overstating active sprawlE14 E15 · A9 · D:C9326Low
R10Journal-entry profile (reworded) — 53 of 88 lifetime JEs are dated 2026 YTD. Per review, this pattern is equally consistent with a young/recently-migrated instance as with acceleration; the causal claim is withdrawn. Confirm go-live date and JE approval policy with the seller's controller.E13 · D:C10236Low
R5AI access governance (amended 12→4) — AI OAuth clients (Claude AI, ChatGPT) have active access. The former "99.8% of traffic" framing was scored on data contaminated by this assessment's own tooling, and "no governance policy" was an absence-of-evidence inference — both corrected per review.残 remaining risk: unverified governance of standing AI access. Seller Q&A item.E16 · A7 · D:C5224Low was 12
R8Residual custom footprint (amended 9→4) — 577 scripts / 183 record types unmatched to known bundles is largely the target's own normal customization, not inherently unmanaged (per review). Residual concern: the genuinely orphaned subset — 626 deployed-not-scheduled + 73 disabled deployments — is hidden-dependency cleanup for phase two.E2 E3 E18 · A1 · D:C8224Low was 9
R11Vendor master decay — 43.6% of vendors lack email; 19.1% inactive. Read together with R1: the vendor master hosts both the decay and the credential exposure — treat holistically in remediation.E7 · D:C11224Low
Account Prenup · TD3016323 · Confidential— 4 —
Section 4

Customization Debt & Key-Person Exposure


Only nine distinct owner identities exist across all 1,169 scripts.E1 The finding here is a bus-factor, stated precisely (and amended after independent review): the owner metadata cannot attribute 87.8% of bespoke code, and of what it can attribute, nearly everything maintainable rests with two or three active individuals.

Local script ownership — 459 scriptsE2

System identity (-5)
403 · 87.8%
T. Dietrich (2 records, A6)
32 · 7.0%
Departed employees (4)
18 · 3.9%
No owner (NULL)
5 · 1.1%
Other active staff
1 · 0.2%
OwnerTotal scriptsLocalStatus
System identity (id -5, account-provisioning admin)1,039403Owner field silent
Ryan Rote (id 1252)707Inactive · no access
T. Dietrich (ids 158 + 3894 — apparent duplicate employee records, A6)4332Active
Ray Gravinese (id 5)88Inactive · no access
E. Goyena (1221) · C. Bermundo (1249)33Inactive · no access
Jacob Bailey (3871)11Active
No owner recorded55Orphaned
Diligence Implication — amended after independent review The owner field's silence on 403 scripts does not by itself mean authorship is lost — scripts deployed via SDF or bundle install routinely land under a provisioning identity, and version history or SDF project sources may exist outside this instance. But those mitigations are unverified here, and what the metadata does establish is stark: the maintainable custom codebase depends on two or three active people, four departed employees still nominally own production automation, and five scripts have no owner at all. The buyer should require (1) a documented handover inventory — entry points, dependencies, business purpose per script — and (2) production of any external SDF repositories or source control, as conditions of transition services.

Deployment surface — 1,915 deployment recordsE3

Deployed · Released (live)
1,175
Deployed · Not scheduled (invocable)
626
Deployed · Scheduled
28
Testing / disabled
86
Terminology corrected per review. The 626 "deployed-not-scheduled" deployments are not dormant — user-event, RESTlet, and on-demand scheduled deployments in this state remain invocable. The 73 disabled and any genuinely orphaned deployments are cleanup targets for the phase-two code review. Known local application families (prior survey, S-2): the bespoke PROMO-PRODUCTS app (including the R1 credential field), the Sonar agent suite, SuiteQL Query Tool 2026, CRM/POS demo apps, dashboard tooling. Ownership of the Org Browser, ATB, and RAC families is uncertain — seller Q&A.
Account Prenup · TD3016323 · Confidential— 5 —
Section 5

Vendor Lock-In & License Posture


52.7% of the customization estate (847 of 1,607 objects) is owned by installed SuiteApps.E18 Four are structurally core — tax computation, fixed-asset depreciation, warehouse execution, shop-floor data capture. Object count is a proxy for runtime criticality (per review note), but tax and fixed assets are load-bearing by construction. Migration cost concentrates here.

Bundle footprint — customization objects (record types + scripts)

SuiteTax Engine / Reporting
216
Fixed Assets Management
175
Ship Central / PackShip
154
Manufacturing Mobile
149
Electronic Bank Payments
75
Benchmark / Cash / Item 360
49
Atlas / SuiteSuccess
29
1,607 CUSTOM OBJECTS
Bundle-owned — 847 (52.7%)
Local / unmatched — 760 (47.3%)

The 760 residual objects are largely the target's own normal customization (per review, R8 amended) — including the bespoke PROMO-PRODUCTS family and internal tooling. Attribution basis: A1.

License-tier signalsE14 E15 E16 · A9

SignalMeasuredImplication for buyer
Provisioned full-access users21 of 30 active employees≈21 seats to novate or renegotiate; 70% provisioning ratio
Custom roles76Permission-review effort scales with roles; consolidation candidate; SoD unassessed (U3)
Premium SuiteApps in use4 structurally coreSuiteTax, FAM, Ship Central, Mfg Mobile — confirm SuiteApp licensing transfers
OneWorld + Advanced modulesSubsidiaries, Multi-Loc Inventory, Work Orders, Adv. PrintingMid-tier-plus edition; reconcile to the license schedule (A9)
Named OAuth clients3 (2 AI, 1 SuiteTalk)AI clients hold standing access — governance unverified (R5); TBA callers invisible (U2)
Account Prenup · TD3016323 · Confidential— 6 —
Section 6

Data Quality Scorecard


76.8 / 72.7 UNWEIGHTED / MATERIALITY-WEIGHTED 0 100

Two composites are shown per the independent review's methodological challenge (D:C12): the unweighted mean of six domain scores (76.8) and a materiality-weighted alternative (72.7) that weights financially significant domains more heavily. Formulas and weights: Section 8, A3/A11. The unweighted design flatters the estate; both are disclosed.

The bifurcation thesis survives review unchallenged (D:C13 confirmed): operational data is excellent; analytical dimensions are materially incomplete.

Contacts
99.2
Open-order hygiene
94.8
Transaction dimensions
78.0
Vendor master
68.6
Customer master
60.3
Item master
60.2

Underlying measurements — all reproducible via Appendix B

MetricEvidencen / NGapReading
Items missing class (worst field — flagged per D:C12)E9307 / 33890.8%High
Customers missing payment terms (worst field)E5219 / 27479.9%High
Customers missing sales repE5208 / 27475.9%High
Vendors missing emailE741 / 9443.6%Medium
FY2026 posting txns with dept-less lines (see R3 caveat)E12717 / 2,34930.5%High
Items missing descriptionE996 / 33828.4%Medium
FY2026 posting txns with location-less linesE12317 / 2,34913.5%Medium
Open POs > 90 daysE113 / 358.6%Medium
Open SOs > 90 daysE101 / 571.8%Strong
Customers missing emailE53 / 2741.1%Strong
Duplicate active customer namesE60 / 2740.0%Strong
Contacts missing emailE80 / 1950.0%Strong
Note on materiality. Master files are small (274 customers, 338 items); full remediation of the High-gap metrics is an estimated days-scale effort, not months. The dimension gaps matter chiefly because they degrade departmental P&L and product-category reporting the buyer will want post-close. The item-count instability (R12) must be resolved before remediation is scoped.
Account Prenup · TD3016323 · Confidential— 7 —
Section 7

Recommended Actions & Unassessed Areas


PriorityActionAddressesTimingEst. effort
1Rotate all credentials stored in CUSTENTITY_PS_PASSWORD; migrate to a secrets store (or NetSuite API Secrets); purge field historyR1Pre-close1–2 days + vendor coordination
2Require seller to produce the complete integration inventory — Setup > Integrations records, all active TBA tokens with their scopes and callers, and RESTlet caller mapping. This is the largest diligence blind spot (U2) and cannot be closed from outside.R7, R5, U2Pre-closeSeller info request + 2–3 days review
3Contractually require a script handover inventory (purpose, entry points, dependencies) for the 403 system-attributed local scripts, plus production of any external SDF repositories / source control; include key-developer transition servicesR2, R8Pre-close / SPA2–4 weeks seller-side; SPA clause buyer-side
4Root-cause the item-master shrinkage (374→338 in 15 days): system notes on deleted/inactivated items, or seller explanation. Re-measure at signing.R12Q&A phaseHalf-day + seller response
5Confirm SuiteApp license transferability (SuiteTax, FAM, Ship Central, Mfg Mobile) and seat count (≈21) against the NetSuite contract and change-of-control clausesR4, R9Pre-closeContract review; NetSuite AM query
6Obtain consolidation-integrity evidence: intercompany balance reconciliation, elimination JE review for the xElim subsidiary, consolidation configuration walkthrough (U1)U1Financial DDRoute to financial diligence team
7Remediate customer terms/rep assignment and item classification; confirm whether department is deliberately unused (R3 caveat) before enforcing dimensions on posting transactionsR3, R6, R11Close + 90d3–5 days data work + config
8Seller Q&A: go-live date and JE approval policy (R10); AI-client access scope and governance policy (R5); ownership of Org Browser / ATB / RAC script familiesR10, R5, R2Q&A phaseThree Q&A items

Unassessed areas — disclosed blind spots, deliberately not scored

Per the independent review, blind spots must not be converted into scored findings. These areas could not be assessed by this method and require the listed follow-up. Absence from the register is not evidence of absence of risk.

IDAreaWhy unassessedRequired follow-up
U1OneWorld consolidation & intercompany integrity (xElim subsidiary correctness, elimination JEs)Financial-integrity testing is outside this technical assessment's scopeFinancial DD team: intercompany reconciliation + elimination review (Action 6)
U2TBA-token integration callersintegration record not exposed to SuiteQL; token callers absent from login-audit OAuth namesSeller-produced inventory (Action 2)
U3Segregation of duties / privileged access (admin-role count, web-service role scopes)Not analyzed in this pass despite available role data — noted by reviewerFeasible follow-up query set; recommend permissions-audit workstream
U4Saved-search (939) and workflow (17) ownership & dependencyCollected but not risk-assessed; same authorship-continuity concern as scriptsPhase-two scope alongside the code review
Phase-two workstream (recommended, not scored). Code-level review of the 577 residual scripts — profiling by naming family, entry-point analysis, dead-code detection against the 626 not-scheduled + 73 disabled deployments, plus U3/U4. On change-freeze: the second edition cited "+19 scripts in 15 days" as evidence of active production development; independent review found that basis invalid (approximate baseline — D:C14) and it is withdrawn. A pre-close customization change-freeze remains standard M&A practice and is still recommended — as prudence, not as a measured finding.
Account Prenup · TD3016323 · Confidential— 8 —
Section 8

Scoring Model


Severities are the product of two 1–5 scores assigned against the anchors below, applied to measured evidence — and, in this edition, stress-tested by independent review with all disagreements published (Appendix D). Reasonable professionals may re-score; the inputs are all in Appendix B.

Likelihood anchors (probability the risk manifests as loss within 12 months post-close)

ScoreAnchor
5Already manifesting — the condition is active in current-period data
4Probable — standing condition with routine trigger paths (e.g., any staff departure, any audit)
3Plausible — requires a common but not inevitable event (integration change, re-platforming decision)
2Unlikely — requires an uncommon trigger
1Remote

Impact anchors (consequence if it manifests)

ScoreAnchor
5Security/legal exposure or operational stoppage; potential deal-term consequence
4Material integration/transition cost or loss of critical institutional capability
3Degraded management reporting or meaningful remediation project
2Contained inefficiency; absorbed by BAU administration
1Cosmetic

Bands

Severity = L × I. Critical ≥ 17 · High 12–16 · Medium 7–11 · Low ≤ 6.

Data-quality score formulas (A3, A11)

domain score = 100 − mean(gap₁…gapₙ), where each gap is a completeness failure rate measured by query.

Worked example — Customer master (60.3): gaps = missing email 1.1% + missing terms 79.9% + missing sales rep 75.9% + missing billing address 1.8%; mean = 39.7%; score = 100 − 39.7 = 60.3.

Unweighted composite (76.8) = mean of the six domain scores. Independent review challenged this design as flattering (equal weight to trivial and catastrophic fields/domains — D:C12). Accepted in part; therefore also disclosed:

Materiality-weighted composite (72.7) = Σ(weight × domain score) with weights reflecting financial-reporting materiality: Customer master 25%, Transaction dimensions 25%, Item master 20%, Open-order hygiene 15%, Vendor master 10%, Contacts 5%. Computation: .25×60.3 + .25×78.0 + .20×60.2 + .15×94.8 + .10×68.6 + .05×99.2 = 72.7. Weights are themselves a judgment (disclosed as A11); worst-field flags are shown in the §6 table so no single average conceals a catastrophic field.
Account Prenup · TD3016323 · Confidential— 9 —
Appendix A

Assumptions Register


IDAssumptionBasis / risk if wrong
A1Bundle attribution by script-ID prefix. "Bundle-owned" = script ID matches one of 16 known prefixes: customscript_fam, %ncfar%, _ste_, _str_, _2663_, _9572_, _9997_, _15529_, atlas, packship/shipcentral, mfgmob, b360, cash360, item360, customscript_sc, customscript_ns. Used because this instance's customsegment.frombundle and related provenance fields are empty/unreliable (verified prior survey).Mis-attribution possible both ways; concentration and bundle-share findings robust to modest reclassification.
A2Severity model is likelihood × impact on the Section 8 anchors, assigned by the assessor against cited evidence — then independently reviewed (Appendix D).Analytical judgment; re-scoreable from Appendix B. Review-driven rescores applied to R2, R5, R8.
A3DQ score formula = 100 − mean gap per domain; unweighted composite across 6 domains.Reviewer found the unweighted design flatters the estate; weighted alternative added (A11).
A4Open-order status codes: SO open = status ∉ {G, C, H}; PO open = status ∉ {G, H, C}. "Stale" = trandate before 2026-05-20.NS standard letter codes; verified against this account's data shape.
A5Script owner field ≈ authorship proxy — known-weak. NS assigns owner at creation; SDF deploys and bundle installs land under provisioning identities. Per review: owner-field silence does not prove authorship is lost; external SDF sources/version history may exist (unverified here).R2 reframed accordingly — the finding is bus-factor plus unverified mitigations, not "authorship destroyed."
A6"Tim Dietrich" (id 158) and "Timothy Dietrich" (id 3894) assumed the same individual holding two employee records.Name-based inference — verify with HR. Reviewer note: even unmerged, top-1 concentration is 87.8%.
A7The AI-login data is contaminated by the diligence tooling itself. This assessment runs through an AI OAuth client; a substantial share of the 5,926 Claude AI events is self-generated.Per review (D:C5), the former traffic-share metric was withdrawn as evidence; R5 rescored to Low and reframed as an unverified-governance question.
A8External-caller inventory is a lower bound. The integration record is not exposed to SuiteQL here; TBA-token callers are invisible to this method.Escalated to U2 + Action 2 (seller must produce the inventory) rather than scored as a measured finding.
A9License tier inferred from enabled features, not from the commercial contract (not available to this assessment).Reconcile against the actual license schedule during contract review.
A10Denominators are point-in-time. Item count 338 live vs ≈374 on 08-03; customer 274 vs 273. Gap percentages use same-query denominators.Per review (D:C15), the item drift is escalated to scored risk R12 — disclosure alone was insufficient.
A11Materiality weights for the alternative composite (Customer 25%, Txn dims 25%, Item 20%, Open-order 15%, Vendor 10%, Contacts 5%) are the assessor's judgment of financial-reporting materiality.Different weights shift the composite several points; both composites and all inputs are disclosed so any weighting can be recomputed.
Account Prenup · TD3016323 · Confidential— 10 —
Appendix B

Evidence & Queries


Canonical, re-runnable forms of the evidence queries, rendered to this account's house SuiteQL conventions. Execute in the SuiteQL Query Tool under an administrator role. Results shown as measured 2026-08-18; live re-runs will drift with normal activity. This account's SuiteQL does not support REGEXP_LIKE — prefix matching uses LIKE chains throughout. All arithmetic derived from these results was verified by independent review (Appendix D).

E1Script ownership — all 1,169 scripts, 9 distinct owners
SELECT
    s.owner,
    e.entityid           AS owner_name,
    e.isinactive         AS owner_inactive,
    COUNT(*)             AS script_count
FROM script s
LEFT JOIN employee e ON e.id = s.owner
GROUP BY s.owner, e.entityid, e.isinactive
ORDER BY script_count DESC
Measured: 1,169 scripts, top owner id -5 with 1,039; 4 owners inactive; 5 scripts NULL-owned. (Reviewer cross-check: GROUP BY rows sum exactly to 1,169.)
E2Local (non-bundle) script ownership — concentration basis (A1)
SELECT
    s.owner,
    e.entityid           AS owner_name,
    COUNT(*)             AS local_scripts
FROM script s
LEFT JOIN employee e ON e.id = s.owner
WHERE LOWER(s.scriptid) NOT LIKE 'customscript_fam%'
  AND LOWER(s.scriptid) NOT LIKE '%ncfar%'
  AND LOWER(s.scriptid) NOT LIKE '%_ste_%'
  -- ... repeat NOT LIKE for all 16 bundle prefixes listed in A1
GROUP BY s.owner, e.entityid
ORDER BY local_scripts DESC
Measured: 459 local scripts; owner -5 holds 403 (87.8%); top-3 identities hold 94.8%.
E3Deployment surface by state
SELECT
    sd.isdeployed,
    sd.status,
    COUNT(*)             AS deployments
FROM scriptdeployment sd
GROUP BY sd.isdeployed, sd.status
ORDER BY deployments DESC
Measured: 1,915 total → deployed+RELEASED 1,175, deployed+SCHEDULED 28, NOTSCHEDULED 626 (invocable — see §4 terminology note), TESTING 13, disabled 73.
E4Workflow estate
SELECT
    w.releasestatus,
    COUNT(*)             AS workflows
FROM workflow w
GROUP BY w.releasestatus
ORDER BY workflows DESC
Measured: 17 workflows — RELEASED 10, NOTINITIATING 6, TESTING 1; none inactive.
E5Customer master completeness
SELECT
    COUNT(*)                                                    AS total_customers,
    SUM(CASE WHEN c.email IS NULL THEN 1 ELSE 0 END)          AS missing_email,
    SUM(CASE WHEN c.terms IS NULL THEN 1 ELSE 0 END)          AS missing_terms,
    SUM(CASE WHEN c.salesrep IS NULL THEN 1 ELSE 0 END)       AS missing_salesrep,
    SUM(CASE WHEN c.defaultbillingaddress IS NULL THEN 1 ELSE 0 END) AS missing_bill_addr,
    SUM(CASE WHEN c.isinactive = 'T' THEN 1 ELSE 0 END)        AS inactive_customers
FROM customer c
Measured: 274 total · missing email 3 · missing terms 219 (79.9%) · missing rep 208 (75.9%) · missing bill addr 5 · inactive 1.
E6Duplicate active customer names
SELECT COUNT(*) AS duplicate_names
FROM (
    SELECT c.companyname
    FROM customer c
    WHERE c.isinactive = 'F'
      AND c.companyname IS NOT NULL
    GROUP BY c.companyname
    HAVING COUNT(*) > 1
)
Measured: 0 duplicate names among active customers.
E7Vendor master completeness
SELECT
    COUNT(*)                                             AS total_vendors,
    SUM(CASE WHEN v.email IS NULL THEN 1 ELSE 0 END)   AS missing_email,
    SUM(CASE WHEN v.isinactive = 'T' THEN 1 ELSE 0 END) AS inactive_vendors
FROM vendor v
Measured: 94 total · missing email 41 (43.6%) · inactive 18 (19.1%).
E8Contact completeness
SELECT
    COUNT(*)                                             AS total_contacts,
    SUM(CASE WHEN ct.email IS NULL THEN 1 ELSE 0 END)  AS missing_email,
    SUM(CASE WHEN ct.company IS NULL THEN 1 ELSE 0 END) AS unattached
FROM contact ct
Measured: 195 total · missing email 0 · unattached 3 (1.5%).
E9Item master completeness — item.salesdescription does not exist in this account's SuiteQL; description used
SELECT
    COUNT(*)                                                  AS total_items,
    SUM(CASE WHEN i.class IS NULL THEN 1 ELSE 0 END)        AS missing_class,
    SUM(CASE WHEN i.description IS NULL THEN 1 ELSE 0 END)  AS missing_description,
    SUM(CASE WHEN i.isinactive = 'T' THEN 1 ELSE 0 END)      AS inactive_items
FROM item i
Measured: 338 total · missing class 307 (90.8%) · missing description 96 (28.4%) · inactive 1. Count vs 08-03 survey (≈374): see R12.
E10Open Sales Orders and staleness (A4)
SELECT
    COUNT(*)                                                  AS open_sales_orders,
    SUM(CASE WHEN t.trandate < TO_DATE('2026-05-20','YYYY-MM-DD')
        THEN 1 ELSE 0 END)                                   AS open_over_90_days
FROM transaction t
WHERE t.type = 'SalesOrd'
  AND t.status NOT IN ('G', 'C', 'H')  -- G=Billed, C=Cancelled, H=Closed
Measured: 57 open, of which 1 older than 90 days (1.8%).
E11Open Purchase Orders and staleness (A4)
SELECT
    COUNT(*)                                                  AS open_purchase_orders,
    SUM(CASE WHEN t.trandate < TO_DATE('2026-05-20','YYYY-MM-DD')
        THEN 1 ELSE 0 END)                                   AS open_over_90_days
FROM transaction t
WHERE t.type = 'PurchOrd'
  AND t.status NOT IN ('G', 'H', 'C')
Measured: 35 open, of which 3 older than 90 days (8.6%).
E12FY2026 posting transactions with dimension-less lines (run twice: department / location)
SELECT COUNT(DISTINCT t.id) AS txns_with_deptless_lines
FROM transaction t
JOIN transactionline tl ON tl.transaction = t.id
WHERE t.posting = 'T'
  AND t.trandate >= TO_DATE('2026-01-01','YYYY-MM-DD')
  AND tl.mainline = 'F'
  AND tl.department IS NULL   -- second run: tl.location IS NULL
Measured: denominator 2,349 FY2026 posting txns · dept-less 717 (30.5%) · location-less 317 (13.5%). See R3 caveat: department may be unused by design.
E13Journal-entry volume, lifetime vs 2026 YTD
SELECT
    COUNT(*)                                                  AS total_journals,
    SUM(CASE WHEN t.trandate >= TO_DATE('2026-01-01','YYYY-MM-DD')
        THEN 1 ELSE 0 END)                                   AS journals_2026
FROM transaction t
WHERE t.type = 'Journal'
Measured: 88 lifetime, 53 (60.2%) dated 2026 YTD. Interpretation reworded per review (R10): consistent with a young instance; confirm go-live date.
E14Provisioned users
SELECT
    COUNT(*)                                                  AS active_employees,
    SUM(CASE WHEN e.giveaccess = 'T' THEN 1 ELSE 0 END)      AS provisioned_users
FROM employee e
WHERE e.isinactive = 'F'
Measured: 30 active employees, 21 provisioned (70%).
E15Role inventory
SELECT
    CASE WHEN r.id >= 1000 THEN 'CUSTOM' ELSE 'STANDARD' END AS role_class,
    COUNT(*)                                                  AS role_count
FROM role r
GROUP BY CASE WHEN r.id >= 1000 THEN 'CUSTOM' ELSE 'STANDARD' END
Measured: 109 roles — 76 custom, 33 standard (5 web-service-only). Id-proxy and role type column agree.
E16OAuth client traffic — LoginAudit (A7, A8 — contaminated by assessment tooling; see R5)
SELECT
    la.oauthappname,
    COUNT(*)             AS login_events
FROM LoginAudit la
WHERE la.oauthappname IS NOT NULL
GROUP BY la.oauthappname
ORDER BY login_events DESC
Measured: Claude AI 5,926 · ChatGPT 62 · SuiteTalk REST 14. Per review: this data is self-contaminated (A7) and TBA callers are invisible (A8) — evidentiary use limited to "AI clients hold standing access."
E17RESTlet count
SELECT COUNT(*) AS restlet_count
FROM script s
WHERE s.scripttype = 'RESTLET'
Measured: 183 RESTlets.
E18Bundle-family footprint — pattern, run per family × {script, customrecordtype} (A1)
-- Example: Fixed Assets family. Repeat with each family's prefixes
-- against BOTH script and customrecordtype tables.
SELECT COUNT(*) AS fam_scripts
FROM script s
WHERE LOWER(s.scriptid) LIKE 'customscript_fam%'
   OR LOWER(s.scriptid) LIKE '%ncfar%'
Measured totals (record types + scripts): SuiteTax 216 · FAM 175 · Ship Central 154 · Mfg Mobile 149 · EBP 75 · x360 49 · Atlas 29 → bundle subtotal 847 of 1,607 (52.7%).
E19Saved-search sprawl
SELECT COUNT(*) AS saved_searches
FROM savedsearch
Measured: 939 saved searches — migration-effort signal; ownership unassessed (U4).
Account Prenup · TD3016323 · Confidential— 11 —
Appendix C

Sources & Reconciliation


Source documents

IDSourceDateRole in this report
S-1Live SuiteQL measurement session — three parallel read-only research passes (ownership; data quality; lock-in & license), executed under administrator session against production2026-08-18Primary evidence — all E1–E19 figures
S-2Prior verified account survey (account facts, feature set, org dimensions, custom-record census, local-customization survey incl. the CUSTENTITY_PS_PASSWORD finding)2026-08-03 / 08-05Baseline context; R1 origin; bundle-prefix list (A1)
S-3House SuiteQL style guide (account-specific query conventions)currentQuery rendering standard for Appendix B
S-4Severity computation worksheet (Section 8 formulas applied to E1–E19)2026-08-18All L×I scores and DQ domain scores; deterministic given inputs
S-5Independent cross-model adversarial review — 16 claims audited, arithmetic verification, missed-risk sweep (full packet & verdicts: Appendix D)2026-08-18Third-edition amendments: R2/R5/R8 rescores, R12 addition, R10/C14 rewording, dual composite, Unassessed Areas

Reconciliation — live measurement vs 2026-08-03 survey

FigureSurvey (08-03)Live (08-18)Disposition
Items≈374338−36 (−9.6%) — escalated to scored risk R12 per independent review: unexplained master-data volatility during a diligence window requires root cause, not just disclosure. Seller Q&A (Action 4).
Customers273274+1 — normal growth; immaterial.
Scripts≈1,1501,169Delta not evidentially usable — baseline explicitly approximate (per review, D:C14). Former "active development" claim withdrawn. Change-freeze recommendation retained as standard practice only.
Custom record types437438+1; immaterial.
Why the drift matters. The estate is not in stable measurement — most visibly the item master (R12). Any figure in this report is point-in-time; the SPA should specify a re-measurement date, and the item-count root cause should be resolved before signing.

Methodology & limitations (consolidated)

All figures were measured directly against the production instance on August 18, 2026, via read-only SuiteQL under an administrator session, supplemented by prior verified survey work (S-2), then independently reviewed (S-5). Severity scores are likelihood × impact per Section 8. Limitations: (i) bundle attribution is prefix-based (A1); (ii) the integration record is not exposed to SuiteQL here — external-caller inventory is a lower bound (A8, U2); (iii) script ownership reflects the owner field, a known-weak authorship proxy (A5); (iv) no code-level review of the 577 residual scripts — phase-two workstream; (v) the AI-login data includes this assessment's own tooling traffic (A7); (vi) license conclusions are feature-inferred (A9); (vii) consolidation integrity, SoD, and saved-search/workflow ownership were not assessed (U1, U3, U4).

Account Prenup · TD3016323 · Confidential— 12 —
Appendix D

Independent Review & Dispositions


Review protocol

On 2026-08-18, the complete evidence base (all 19 measurements), the computed metrics with formulas, and the 16 claims of the second-edition register — stated neutrally, with the assessor's recommendations withheld — were submitted to an independent reviewing model operating under an adversarial-review charter: verify all arithmetic; flag claims where evidence does not support the language; flag over/under-scored risks with proposed rescores; identify material risks the register missed. The reviewer's verdicts are reproduced below verbatim in substance, followed by the assessor's disposition of each. Where a disposition is "accepted," the body of this report has been amended accordingly; nothing was silently changed — the amendment log at the end of this appendix is complete.

Provenance (disclosed per protocol): Primary analysis: claude-fable-5 (Sonar AI). Independent review: claude-opus-4-8 via user-supplied API key. Both analyses are LLM-generated; a sibling-model review checks arithmetic, logic, and interpretation but is not fully independent (shared training lineage) and is not a substitute for human review. All arithmetic was independently recomputed by the reviewer and confirmed correct.

Verdict summary — 16 claims

Confirmed
7
Challenged
7
Error
2

Claim-by-claim verdicts and dispositions

ClaimVerdictReviewer's reasoning (substance, verbatim where quoted)Disposition
C1 R1 credentials (20 Critical)Confirmed"Plain-text stored credentials are a live security/legal exposure (I5 defensible). L4 slightly conservative … this is already-manifesting (L5). Rescore L5×I5=25 arguably warranted, but L4 is defensible if likelihood is read as likelihood of breach. Either band is Critical."Accepted. Score retained at 20 with the likelihood-of-breach reading documented in the register row.
C2 R2 key-person (was 16)Challenged"'Authorship untraceable' is overstated. Owner -5 is the system/provisioning identity — scripts deployed via SDF/bundle install commonly land under a provisioning identity; that is not the same as 'authorship unknown.' … The real risk is key-person/bus-factor on the 32 local scripts under the Dietrich identity, not the -5 concentration." Proposed L3×I3=9.Partially accepted — rescored 16→12 (L4×I3). Framing amended to bus-factor; impact reduced accepting that owner-field silence ≠ authorship lost. Likelihood held at 4 over the reviewer's 3: the SDF/version-history mitigations the reviewer cites are unverified in this account, and 4 departed owners + 5 orphans are measured, standing conditions.
C3 R3 dimensions (15)Challenged"Department may be intentionally unused if the org segments by class/location instead … the department finding needs the alternative explanation (segment not in use by design) tested before calling it a defect. Keep High band, add caveat."Accepted. Score retained; design-vs-defect caveat added to the register row and Action 7.
C4 R4 lock-in (12)Confirmed"Bundle dependency is a genuine transition-cost/lock-in risk … object count ≠ runtime criticality, but tax/FA/warehouse are structurally core."Accepted. Proxy limitation noted in §5.
C5 R5 AI egress (was 12)Error"The 99.8% figure is contaminated by the diligence tooling's own traffic … Using a self-generated metric as evidence of the target's AI exposure is circular. 'No governance policy evidenced' is absence-of-evidence used as evidence … Downgrade to informational or L2×I2=4. The ERROR is the reasoning, not the arithmetic."Accepted in full — rescored 12→4 Low. Reframed as unverified-governance seller Q&A item. Executive summary, matrix, and actions amended.
C6 R6 customer master (12)Confirmed"Missing terms and sales rep degrade AR automation and reporting … terms-null may default at transaction time — as a master-data-quality finding it stands."Accepted. Default-at-transaction caveat added.
C7 R7 integrations (9)Challenged"This restates a tooling limitation as a risk … should be labeled as a diligence gap requiring the seller to produce the integration/token inventory, not as a measured finding. Reword; score acceptable."Accepted. Reworded as diligence gap; escalated to Action 2 + U2; score retained.
C8 R8 unclassified debt (was 9)Challenged"'Unattributed' means 'unmatched to the 16 known bundle prefixes,' NOT 'authorship unknown' … expected and largely benign (it's the customer's own customization). Also '1,203 executing deployments' mislabels the metric [NOTSCHEDULED deployments remain invocable]." Proposed L2×I2=4.Accepted — rescored 9→4 Low. Terminology corrected throughout (§2, §4); orphaned-deployment subset (626+73) routed to phase two.
C9 R9 roles (6)Confirmed"Genuine sprawl but low-impact … some roles may be legacy/unassigned — the ratio overstates active sprawl slightly."Accepted. Caveat added.
C10 R10 JE trend (6)Challenged"88 JEs lifetime … implies this instance is young or JEs are rare; 60% being YTD is fully consistent with a recently-migrated/go-live instance, not 'volume acceleration.' Without a go-live date the acceleration narrative is unsupported."Accepted. Causal claim struck; reworded as go-live-consistency question; band unchanged (Low).
C11 R11 vendors (4)Confirmed"Low severity appropriate."Accepted. Cross-reference to R1 added per reviewer's missed-risk note 8.
C12 DQ composite 76.8Challenged"The unweighted mean biases the composite upward and is structurally misleading … a catastrophic field (terms 79.9% null) is averaged against a trivial one (email 1.1% null), diluting severity … A materiality-weighted or worst-field-flagged design would produce a lower, more honest number."Partially accepted. Unweighted composite retained for transparency; materiality-weighted composite (72.7, A11) added alongside it everywhere the score appears; §6 table re-sorted worst-field-first.
C13 Bifurcation thesisConfirmed"The strongest defensible synthesis in the packet."Retained.
C14 Change-freeze basisError"The prior count is explicitly approximate and item count dropped over the same window … the delta is within measurement noise. The change-freeze recommendation may be prudent generally, but this specific evidentiary basis is invalid."Accepted in full. Claim struck from Appendix C; change-freeze retained as standard practice only, explicitly not a finding (§7 note).
C15 Item reconciliation handlingChallenged"A 10% drop in item master in 15 days is itself a material finding (deletions? inactivations? re-migration?) that is dismissed rather than investigated. The reconciliation is disclosed, not explained."Accepted. Escalated to new scored risk R12 (L3×I3=9 Medium) + Action 4.
C16 Overall score supportabilityChallenged"The register systematically converts tooling blind spots into findings (C5, C7, C2's -5 identity), and treats normal custom footprint (C8) as risk. Net effect: inflated High-band count."Accepted in net. High band reduced 5→4; blind spots moved to the Unassessed Areas structure (§7); this appendix documents every change.

Reviewer's missed-risk sweep — dispositions

#Reviewer findingDisposition
M1"Item master shrinkage (374→338, −9.6% in 15 days) is a risk, not a footnote."Accepted → new risk R12 (Medium) + Action 4.
M2"Elimination subsidiary / OneWorld consolidation integrity untested … a core M&A financial-integrity area entirely absent."Accepted → U1 + Action 6, routed to financial DD. Deliberately not scored (scoring an untested area would repeat the absence-of-evidence error).
M3"Disabled/orphaned deployments (73 + 626 not-scheduled) never flagged — real cleanup and hidden-dependency risk."Accepted → folded into amended R8 and the phase-two scope; §4 terminology corrected.
M4"Effectively the entire maintainable custom codebase depends on one or two active people. This bus-factor risk is stronger than the -5 concentration C2 leans on."Accepted → R2 reframed around exactly this; §4 rewritten.
M5"TBA/token integration surface entirely unquantified … the single largest diligence blind spot; escalate to a seller information request."Accepted → promoted to Action 2 (second-highest priority) + U2.
M6"No segregation-of-duties / privileged-access analysis despite having role and giveaccess data."Accepted → U3. Feasible with available data; recommended as a dedicated permissions-audit workstream rather than a rushed addendum.
M7"Saved searches (939) and workflows (17) collected but never risk-assessed for ownership/dependency."Accepted → U4 + phase-two scope.
M8"Vendor master is arguably the highest-risk object in the estate (R1 credentials + R11 decay) and isn't treated holistically."Accepted → cross-references added to R1/R11; remediation Actions 1 and 7 treat the vendor master as one workstream.

Reviewer's bottom line (verbatim)

"Arithmetic is essentially clean throughout. The analytical weaknesses are (a) repeatedly converting tool blind spots into findings (C5, C7, partly C2/C8), (b) an unweighted DQ composite that flatters the estate (C12), (c) two unsupported causal narratives (C10 acceleration, C14 change-freeze basis), and (d) a genuine missed cluster around consolidation integrity, item-master volatility, and bus-factor."

All four weakness classes have been remediated in this edition as documented above. No reviewer verdict was rejected outright; one (C2) was accepted in part with a documented, reasoned divergence on the likelihood score.

Amendment log — second edition → third edition

#ChangeDriver
1R2 rescored 16→12; reframed from "authorship untraceable" to development bus-factor; §4 rewrittenC2, M4
2R5 rescored 12→4; AI traffic-share metric withdrawn as evidence; reframed as unverified-governance Q&A itemC5 (Error)
3R8 rescored 9→4; "unattributed = unmanaged" conflation corrected; "1,203 executing" terminology corrected (626 not-scheduled remain invocable)C8, M3
4R12 added (item-master shrinkage, 9 Medium); Appendix C reconciliation row escalatedC15, M1
5R10 causal "acceleration" claim struck; reworded as go-live-consistency questionC10
6"+19 scripts → change-freeze" evidentiary claim withdrawn; change-freeze retained as standard practice onlyC14 (Error)
7Materiality-weighted composite (72.7) added alongside unweighted (76.8); §6 table re-sorted worst-field-first; A11 addedC12
8Unassessed Areas structure added (U1–U4: consolidation integrity, TBA tokens, SoD, saved-search/workflow ownership); blind spots no longer scoredC16, M2 M5 M6 M7
9R3 design-vs-defect caveat; R6 terms-default caveat; R9 legacy-roles caveat; R1/R11 vendor-master cross-reference; R4 object-count-proxy noteC3 C6 C9 M8 C4
10Actions reprioritized: seller integration-inventory request elevated to Priority 2; item-shrinkage root cause added as Priority 4; consolidation evidence added as Priority 6M5 M1 M2
Account Prenup · TD3016323 · Confidential · Third Edition— 13 —