Selected work
Described without identification of clients, in accordance with our engagement terms. Two concern errors of our own.
An audit answered from the client’s own logs
An energy services company asked to demonstrate who had modified a firewall rule and when. Because every engineer held a named account, the answer came from their directory audit log rather than from anything we asserted.
Our own error, logged before it was noticed
An engineer applied a group policy change with a wider scope than intended and corrected it the same afternoon. Both the error and the correction were written up before the client raised it.
An environment inherited from nine shared logins
A transition from a provider whose whole team used one administrator account. Discovery took considerably longer than usual because the change history could not be reconstructed at all.
An outage traced through the record
A failure caused by a configuration change made fourteen months earlier. The record held the previous value, which made the rollback a ten-minute task rather than an afternoon.
Documentation only
An organization keeping support in house that wanted its environment recorded properly. We produced the documentation and took no ongoing support role.
A risk we recommended leaving alone
An ageing server supporting a line-of-business application with no supported upgrade path. Replacing it would have cost more than the risk justified, and we said so.
Taking on an inherited environment
Most environments we take on were built and maintained by someone else, frequently without a usable record. That is the normal starting position rather than an exception.
We do not blame the previous provider. Shared administrator accounts and undocumented changes are industry-standard practice, and an incoming provider criticising the outgoing one is usually managing the client’s expectations rather than describing reality.
Discovery establishes what exists. Servers, network equipment, cloud tenants, applications, licences, and vendor relationships are catalogued as found, and the gaps are listed as gaps rather than quietly filled with assumptions.
The baseline is recorded before we change anything. This matters more than it sounds: without it, the first months of our change log would have nothing to describe changes against.
Where history cannot be reconstructed, we say so. Some environments simply cannot be explained, and pretending otherwise would be the same failure the client is trying to move away from.
What we go through with you
The change record for the period. Everything altered in your environment, by whom, and when, with the previous values retained. Most months this is unremarkable, which is the intended result.
A reconciliation against your own audit logs. We compare our written record to what your directory recorded independently. Where the two disagree, the gap is investigated and reported, including when the omission was ours.
Restore testing results. Which backups were tested, whether they restored, and how long the restore took. A backup completing successfully and a backup restoring successfully are different claims, and only the second one matters.
The risk list, revisited. What we still consider urgent, what has moved, and what we continue to recommend leaving alone. Items are removed from the list when they are resolved rather than accumulating indefinitely.
Anything we got wrong. Errors made during the month, what they affected, and what was done about them. These appear whether or not you noticed them.