Project Invisible Risk
Full-Codebase Discovery - Finding What a Sampled Assessment Misses
The Challenge
A transaction-processing operator handling high-volume payments needed a technical assessment of its core platform - 97 projects across 17 modules - before deciding whether to proceed with a full ERP implementation programme. A prior assessment based on interviews and code samples had missed what a full scan later found.
What I Built / Delivered
Ran AI-assisted analysis across all 97 projects and 17 modules - not a sample. Mapped all inbound, outbound, and internal data flows with 0-100% assurance indicators, and extracted 100+ business rules from the codebase directly rather than from documentation. The full scan surfaced 529 unauthenticated REST endpoints nobody on the client side knew existed. Directed audit cycles identifying and correcting factual errors before client presentation.
The Outcome
The 529 unauthenticated endpoints - invisible to the prior sampled assessment - became the client's top remediation priority. Zero misleading claims delivered to the client. The technical due diligence was comprehensive enough to underwrite the ERP investment decision and specific enough to inform the implementation roadmap.
Why This Matters
The gap between "sampling" and "full analysis" is exactly where risk hides. Enterprise AI applied to the hardest engineering problem: understanding 97 interconnected projects well enough to find what a partial assessment - human or AI - would have missed.