Scenario 1 · Independent AI Project Audit

Three weeks in, and you still cannot tell whether anything is being built.

The updates sound fine. The demo looked fine. But you are paying for a system you cannot evaluate, from a person you cannot supervise, and the only thing you know for certain is that you were supposed to be further along by now. An independent audit gives you a qualified read in five business days.

Sound Familiar?

The things owners say on the first call.

Every line below is close to something a real client told us in the last 90 days.

"He sends me documents. Big ones. I do not know what any of it means and I am embarrassed to ask again."

"It's been three weeks and I'm still where I was three weeks ago."

"There is a dashboard. It shows me my Facebook numbers. I could already see my Facebook numbers."

"He said he had a platform already built that he plugs clients into. Now it seems like everything is being built from scratch."

"The plan has seven components. Four say 'fully built.' I have never seen any of them do anything."

"I think he is smart. I just do not think he knows what a business needs, and I cannot tell how much of this the AI is writing for him."

What We Audit

Six areas. One table. No jargon without a translation.

1. Promised versus delivered

We line up the proposal, the invoices, and the messages against the working system. Each item gets one of four marks: delivered, partial, planned, or "information in a new place." You see the whole engagement on one page.

2. Access and ownership

Domain, DNS, hosting, repository, cloud accounts, spreadsheets, API keys, subscriptions. Who holds each one, whether you are an administrator, and what breaks if the vendor disappears on a Friday.

3. Architecture and hosting

Where does it actually run? Their Render account, your Cloudflare, a laptop? Is it a system or a set of disconnected pieces? Can it be moved, and what would it take?

4. Security and exposure

Keys in code, credentials in chat threads, customer data in a shared sheet, a public site with no accessibility layer, AI connected to a mailbox it should never see. We list every exposure and how to close it.

5. Real work versus generated work

Modern tools let anyone produce an impressive planning document in ten minutes. We separate what was built and tested from what was described, and we tell you honestly whether the person is steering the AI or being steered by it.

6. Spend versus value

What you paid, what you are still paying monthly (the subscriptions they started in your name count), and what the working parts would cost to recreate. Sometimes the honest answer is that a rebuild is cheaper than the next invoice.

The Deliverable

The Audit Report.

Written for the owner, not for another engineer. Every section has a plain English summary first and the technical detail after it.

SectionWhat it answers
One-page verdictOn track, at risk, or stalled. The three things to do this week. Whether it is safe to keep paying.
Promised versus delivered tableEvery commitment from the proposal and the messages, with its status and the evidence we found.
Access and ownership registerEvery account and key, who holds it, and the exact step to bring it under your control.
Security findingsExposures ranked by severity, each with the fix and who should do it.
Spend reviewPaid to date, recurring charges started by the vendor, and what the working parts are worth.
RecommendationKeep the vendor with a checklist, fix what exists, or rebuild on accounts you own. With the reasoning and a cost range for each.
Vendor checklistIf you keep them: the list of items, in order, that they need to complete before the next payment.
Process

Five business days, start to report.

  1. 1

    Day 1: Intake and inventory

    You submit the form below and forward the emails you sent the vendor. We build the access inventory and send you a short list of what to request or share. A secure vault is set up for any credentials, so nothing lives in email.

  2. 2

    Days 2 to 3: The review

    Repository, hosting, automations, data, and documents. A 45-minute screen share with you to see the system the way you see it, and a call with the vendor if you want one.

  3. 3

    Day 4: Findings drafted

    We write the report and check every finding against evidence. Nothing goes in the table without a screenshot, a commit, a URL, or a line in a message.

  4. 4

    Day 5: Walkthrough

    A one-hour call where Michael walks you through the report, answers everything, and you leave with a decision. The report is yours to share with anyone.

From a recent audit

"All he's doing is just taking the credentials that you've given him and feeding you what they say. It's just information, but it's not accomplishing anything. This is just information in a new place."

Michael Bowers, reviewing a client's "AI command center" live on the discovery call. Read the case study.

"He hasn't done anything wrong. I just think that he's following AI too much to guide him, not really understanding what needs to be done."

Michael Bowers, same call. The most common audit finding is not fraud. It is a capable person out of their depth.
Pricing

Fixed fee, quoted from the intake within one business day.

Audits are priced to the size of the project, not the size of your company. A single freelancer build is a small audit. A multi-vendor platform with six integrations is a larger one. Either way the number is fixed before we start, and it is a fraction of what you have already spent. Standard hourly is $250 if you would rather buy time. The Continuity Call that closes a vendor handoff is a flat $399 and can be added to any audit.

Audit Intake

Request an independent audit.

The more you tell us, the tighter the quote. Nothing here is shared with your vendor.

About you
The project
What you can see today
What the vendor has access to (check every one that applies)

Tip: the emails you sent them are the fastest inventory. Forward them to us after you submit and we reconcile the list.

How you want this handled

Confidential. Nothing you share is used for anything except answering you. No spam and no sales calls unless you ask for one.

FAQ

Questions we hear on the first call.

Do I need to tell my developer you are auditing?

Not necessarily. If you can give us read access to the accounts and the repository, we can do most of the audit quietly. If we need to talk to them, we tell you first and you decide how it is framed. Many clients present it as a normal continuity review, which is exactly what it is.

What if I do not have access to anything?

Then that is the first finding, and it moves you to the takeover page. Most audits start with a short access exercise: you forward the emails you sent the vendor, we build the inventory, and you request administrator access on each one. How the vendor responds tells us a lot.

Will you read the code?

Yes. Michael reads the repository, the deployment configuration, the automations, and the prompts if it is an AI system. He has 25 years of IT and security work and builds these systems himself. If the deliverable is a document describing code that does not exist, that is a finding.

What if the audit says the project is fine?

Then you have paid a small amount to sleep, and you have a written list to hold the vendor to for the rest of the engagement. About a third of audits end with 'keep going, here is what to insist on.'

Can I use the report in a dispute or refund request?

The report is factual and written in plain English, and clients have attached it to disputes. It is not a legal opinion. If it comes to that we are happy to walk your attorney through it at our hourly rate.

How is this different from the Operations Diagnostic?

The Operations Diagnostic looks at your whole business and asks where AI should go. The audit looks at one project someone is already building and asks whether it is going anywhere. Different question, different price.