System Audit
Conduct comprehensive evaluation of system architecture and identify improvement opportunities.
Context
You are auditing a system's architecture. Assess design quality, technical debt, operational readiness, scalability potential. Read code, infrastructure, metrics, team feedback.
Domain Context
Based on architecture assessment frameworks:
- Design Quality: Modularity, coupling, cohesion. Is architecture aligned with business domains? Easy to change?
- Operational Readiness: Monitoring, alerting, logging, runbooks. Can ops team run this effectively? What happens when it fails?
- Scalability: Can it handle 10x growth? What's the bottleneck? Vertical or horizontal scaling?
- Technical Debt: What's slowing teams down? What would refactoring improve?
- Security and Compliance: Data protection, access control, audit trails, regulatory alignment?
Instructions
Prepare Audit Checklist:
- Architecture & Design (modularity, coupling, domain alignment)
- Data (model, storage, flow, governance)
- Scalability (bottlenecks, growth headroom)
- Operations (monitoring, logging, alerting, runbooks)
- Security & Compliance (data protection, access control, audit)
- Team Productivity (deployment time, testing capability, cycle time)
Gather Information:
- Read architecture documentation, design documents
- Review code structure, dependencies
- Check infrastructure-as-code, deployment pipelines
- Interview team: "What's hard? What's slow? What worries you?"
- Review metrics: latency, error rate, utilization, deployment frequency
Assess Each Area:
- Score: Good (no action needed), Fair (monitor, improve over time), Poor (urgent)
- Document evidence: "Monolith 500K lines, 30-min builds, hard to test"
Identify Patterns:
- Common themes? Multiple "poor" scores suggest systemic issues.
- Root causes: "Tight coupling causing hard deployments and scaling issues"
Recommend Improvements:
- Prioritize by impact and effort
- Quick wins (low effort, high impact): improve monitoring, document runbooks
- Strategic initiatives (high effort, high impact): decompose monolith, refactor critical paths
- Timeline: what's urgent vs 2-year plan?
Document and Present:
- Written report with findings and recommendations
- Present to leadership and team
- Create roadmap for improvements
- Follow up in 6 months to measure progress
Anti-Patterns
- Audit Without Action: Produce report, file it away. Result: wasted effort, team cynicism. Guard: Use audit to drive improvements; track follow-up.
- Oversimplified Scoring: Everything is "good" or "poor" with no nuance. Result: not actionable. Guard: Explain context; acknowledge tradeoffs; show path forward.
- Ignoring Team Input: Audit from outside perspective only. Result: miss what team actually struggles with. Guard: Interview team; their perspective is crucial.
- Unrealistic Recommendations: Suggest complete rewrite. Result: ignored, too ambitious. Guard: Suggest achievable improvements; prioritize by ROI.
Further Reading
- Software Architecture in Practice by Len Bass et al. — architecture evaluation methods
- Assessing Organizational Alignment — evaluating organizational health
- Technical Debt Management — evaluating debt and improvement priorities
1---2name: system-audit3description: Conduct comprehensive system architecture evaluation. Assess design quality, technical debt, operational readiness, scalability. Use when auditing existing systems.4---56# System Audit78Conduct comprehensive evaluation of system architecture and identify improvement opportunities.910## Context1112You are auditing a system's architecture. Assess design quality, technical debt, operational readiness, scalability potential. Read code, infrastructure, metrics, team feedback.1314## Domain Context1516Based on architecture assessment frameworks:1718- **Design Quality**: Modularity, coupling, cohesion. Is architecture aligned with business domains? Easy to change?19- **Operational Readiness**: Monitoring, alerting, logging, runbooks. Can ops team run this effectively? What happens when it fails?20- **Scalability**: Can it handle 10x growth? What's the bottleneck? Vertical or horizontal scaling?21- **Technical Debt**: What's slowing teams down? What would refactoring improve?22- **Security and Compliance**: Data protection, access control, audit trails, regulatory alignment?2324## Instructions25261. **Prepare Audit Checklist**:27 - Architecture & Design (modularity, coupling, domain alignment)28 - Data (model, storage, flow, governance)29 - Scalability (bottlenecks, growth headroom)30 - Operations (monitoring, logging, alerting, runbooks)31 - Security & Compliance (data protection, access control, audit)32 - Team Productivity (deployment time, testing capability, cycle time)33342. **Gather Information**:35 - Read architecture documentation, design documents36 - Review code structure, dependencies37 - Check infrastructure-as-code, deployment pipelines38 - Interview team: "What's hard? What's slow? What worries you?"39 - Review metrics: latency, error rate, utilization, deployment frequency40413. **Assess Each Area**:42 - Score: Good (no action needed), Fair (monitor, improve over time), Poor (urgent)43 - Document evidence: "Monolith 500K lines, 30-min builds, hard to test"44454. **Identify Patterns**:46 - Common themes? Multiple "poor" scores suggest systemic issues.47 - Root causes: "Tight coupling causing hard deployments and scaling issues"48495. **Recommend Improvements**:50 - Prioritize by impact and effort51 - Quick wins (low effort, high impact): improve monitoring, document runbooks52 - Strategic initiatives (high effort, high impact): decompose monolith, refactor critical paths53 - Timeline: what's urgent vs 2-year plan?54556. **Document and Present**:56 - Written report with findings and recommendations57 - Present to leadership and team58 - Create roadmap for improvements59 - Follow up in 6 months to measure progress6061## Anti-Patterns6263- **Audit Without Action**: Produce report, file it away. Result: wasted effort, team cynicism. **Guard**: Use audit to drive improvements; track follow-up.64- **Oversimplified Scoring**: Everything is "good" or "poor" with no nuance. Result: not actionable. **Guard**: Explain context; acknowledge tradeoffs; show path forward.65- **Ignoring Team Input**: Audit from outside perspective only. Result: miss what team actually struggles with. **Guard**: Interview team; their perspective is crucial.66- **Unrealistic Recommendations**: Suggest complete rewrite. Result: ignored, too ambitious. **Guard**: Suggest achievable improvements; prioritize by ROI.6768## Further Reading6970- _Software Architecture in Practice_ by Len Bass et al. — architecture evaluation methods71- _Assessing Organizational Alignment_ — evaluating organizational health72- _Technical Debt Management_ — evaluating debt and improvement priorities