Engagement
From scope letter to findings workshop
Application audits fail when boundaries stay vague. This page shows the sequence we use so owners know when interviews happen, what evidence we expect, and how disagreements are handled before the report is final.
Scoping conversation
You name the applications, the reason for the audit, and any fixed external date. We ask about environments, owners, and whether evidence exports already exist. This call is not billed.
Scope letter and fee
We issue a letter listing in-scope applications, control themes, sample periods, deliverables, timeline, and fee. Work starts only after written acceptance and the deposit invoice.
Evidence request list
A structured request covers inventories, access exports, change tickets, backup logs, and vendor contracts. We agree formats that your teams can actually produce within the calendar.
Interviews and walkthroughs
We sit with application owners and operators — often in Miyagi, sometimes by video — to test whether procedures match the screenshots. Anomalies are noted with evidence references, not hallway gossip.
Findings workshop
Before the report is locked, we walk through draft observations. Clients may provide clarifying evidence. We do not remove a finding without a documented reason; we may reclassify severity when evidence supports it.
Final pack and handover
You receive the management summary, detailed findings, evidence index, and remediation roadmap. Optional follow-up days can verify closed items; they are scoped separately.
Practical notes
Calendars, language, and access
- We avoid major evidence pulls during your month-end close unless you insist.
- Findings can be delivered in English, Japanese, or a dual pack — confirmed in the scope letter.
- Read-only access is preferred; when that is impossible, supervised screenshots are acceptable if timestamps are visible.
- We will not install monitoring agents or alter application configuration.