Note
We can start from a blank page. We would rather not. The quality of a control-application audit tracks the quality of what you can show us in the first two days.
A useful pack is boring:
- A network sketch that includes the broker, the gateways, and the operator devices, even if it is a photo of a whiteboard.
- A list of control applications (vendor name, version, who pays the licence).
- Role names as the app knows them, not as HR knows them.
- One example of a change ticket, even a messy one.
- MQTT or API documentation if it exists; a capture if it does not.
- Named contacts for operations, IT, and the integrator, with who can authorise a test write.
Do not wait for a perfect CMDB. Do not redact so hard that we cannot see a hostname. Mark secrets and give them to us on paper at the site if you prefer; we do not need passwords in email.
If you are requesting a scoping conversation, you do not need this pack yet. If you have already booked a command-path audit, sending it a week ahead means we spend the first morning on the line instead of reconstructing how the tablet talks to the pump.