Architecture audit
The Blobb Architecture Audit
An independent review of your architecture, infrastructure, and delivery path. It can cover the full system or a specific question, billed hourly or as a fixed commitment. You keep the findings whether or not you engage Blobb again.
What it is
An audit is a structured review of a system that is already in production, conducted by people who have built, run, and paid for systems of the same shape.
It answers three questions. Where is money leaving the platform without buying anything. What is going to slow the engineering team down as the business grows. What would it cost to fix each of those, and in what order.
Nothing is recommended before it is measured. Findings are handed over with severity, effort, and an owner against each one, so the list can be worked rather than admired.
Who it is for
- A system that has been in production for several years and now costs more to change than it used to
- An infrastructure bill growing faster than the business behind it
- A modernization program that needs an independent baseline before budget is committed
- A board or an investor asking for a technical assessment ahead of a decision
- A new technology leader who needs an honest map of what they have inherited
Blobb does not need permission from the incumbent team to be useful, and does not report on individuals. The subject of the audit is the system.
The five review lenses
A full audit is read through the same five lenses. They are applied in the order that matters for your situation, and the weighting is agreed before the work starts. A focused review uses the lenses relevant to its question.
Cost and commercial efficiency. What the platform costs to run today, what it will cost at the growth the business is planning, and which parts of the spend are buying nothing. Purchasing models, commitment horizons, and lock-in exposure are modelled rather than asserted, with break-even points stated so the choice stays with you.
Operational excellence and delivery velocity. The path from a committed change to a change in production. Release procedure, environment separation, automation coverage, and the toil a team actually carries week to week. In most engagements the ceiling on delivery speed is here, not in headcount.
Reliability and failure containment. What happens when a dependency is slow, a region is unavailable, or load arrives faster than planned. Blast radius, degradation behaviour, and whether the system fails in a way the business can absorb.
Performance and scaling headroom. Where the time actually goes, measured on the paths that carry the most volume, under conditions that resemble real use rather than a developer laptop. The distance between current load and the point where something has to change.
Security and access posture. Identity, secrets, network boundaries, data handling, and the gap between the controls that exist and the controls a customer or a regulator will ask about.
How the review runs
A full audit normally takes three to five weeks. A focused review uses the parts of this process needed to answer the agreed question.
- Discovery, remote. Inventory of accounts, workloads, and dependencies. Twelve months of billing and utilization data. Architecture and dependency mapping. Inspection of infrastructure-as-code coverage and the build pipelines. Read of the code paths that carry the most volume.
- Embedded, with the team. Structured interviews with the people who own the platform, the releases, and the on-call rotation. The deployment path walked end to end. Direct observation of the work the team does to keep the system running. This phase is on site where it is worth the trip, and remote where it is not.
- Modelling and readout. Each option costed and scored on saving, effort, risk, and reversibility, then benchmarked against current practice and credible alternatives. Two readouts: one for the engineering team, one for the executive sponsor. They contain the same findings and answer different questions.
How findings are classified
Immediate. Can be actioned inside weeks by the existing team, with a known effort and a low risk of regression. Usually configuration, purchasing, or a contained change.
Structural. Requires a funded project and a decision. Carries the larger gains and the larger bill. Costed rather than assumed away.
Watch. Not a problem today. Becomes one at a threshold that is named, projected against the growth plan the business has already committed to.
What you receive
A full audit includes the complete set below. For a focused review, the proposal identifies the smaller set of outputs needed to answer the agreed question.
- A findings register. Every finding with severity, effort, expected gain, and a named owner on your side.
- A costed option set. For each material decision, the credible options with break-even, commitment horizon, and lock-in exposure stated plainly.
- An executive brief. The current estate read against modern practice and the alternatives, written for a reader who does not work in engineering.
- A re-architecture outline. Target shape, sequencing, expected gain, and the cost to get there. Enough to build a business case from.
- A ninety-day action list. Split between what your team can execute unaided and what needs a funded project.
These are your documents. There is no obligation to engage Blobb for anything that follows.
What it costs
Hourly engagements start with US$5,000 of agreed volume. A focused review can begin there; it does not have to become a full audit.
Most audits are billed hourly. Before work starts, Blobb estimates the time required from the size of the estate, the number of systems, the depth of the code read, and the question you need answered. This is the more flexible option when priorities may change as evidence emerges, though it requires more time and budget tracking on your side.
If you prefer budget certainty and less ongoing administration, the same time estimate can be turned into a fixed commitment with written scope and assumptions. The pricing basis is the same; the difference is contractual. Travel is billed at cost where an on-site period is agreed.
Blobb does not resell software, does not hold reseller margin, and does not take commission from any vendor named in a finding. The recommendation and the invoice are unrelated.
What we need from you
- Read access to the cloud accounts or infrastructure in scope, and to twelve months of billing data
- Read access to the source repositories and the CI configuration in scope
- Access to existing monitoring and any prior architecture documentation, however out of date
- Roughly six to eight hours in total from the people who own the platform, releases, and on-call rotation
- One executive sponsor who can say what the business is optimizing for
A mutual NDA can be in place before any of this is shared. Blobb’s standard mutual NDA and completed security questionnaire are available for download.
What happens after the audit
Three normal outcomes.
Your team executes. The action list is written to be worked without Blobb. Many clients take this path for the immediate findings and revisit the structural ones later.
A scoped optimization. A narrow, defined piece of work with a measurable target. Blobb implements alongside your engineers rather than in place of them, and each change is measured against the baseline before the next is started.
A re-architecture program. Blobb plans and leads the modernization, in a fractional CTO or lead architect capacity, working to the sequence the audit established.
Common questions
How long does it take?
A full audit normally takes three to five weeks, part-time and embedded, so your team is not blocked waiting on it. A focused review is scheduled around the question and access required.
Do you need to be on site?
Not always. Where an on-site week materially improves the result, Blobb will say so in the proposal and price the travel separately.
What if the audit finds nothing significant?
Then the report says so, in writing, and you have an independent baseline to point at. That is a legitimate result and it has been the outcome before.