The first day
- Can it be run locally? If not, that is the first problem
- Is it in version control? With history, ideally
- Are dependencies current? Audit for known vulnerabilities
- Are there tests, and do they pass?
- What is about to expire? Credentials, certificates, unsupported versions
The fifth is the urgent one. An expiring credential or an unsupported Python version is a deadline you inherited without being told about it.
Then understand what it does
- What triggers it — schedule, request, event
- What it reads and what it writes
- What external services it depends on
- What happens when each of those fails
- Who currently relies on its output
Get it under control before changing it
- Version control, if it is not already
- A local environment that works, documented
- Characterisation tests around the important behaviour
- Monitoring, so you know if it stops
- A backup of whatever it depends on
Changing code you do not understand, with no tests and no monitoring, is how inherited systems break in the first month.
Common findings
| Finding | Frequency |
|---|---|
| Credentials in the repository | Very common |
| Dependencies years out of date | Very common |
| No tests | Common |
| No monitoring | Common |
| Runs on one person's machine | More common than you would hope |
Write down what you find
A one-page summary: what it does, what it depends on, what is wrong, what is urgent. That document is worth having whether you keep, fix or replace the system.
It is also what lets a non-technical owner decide what to fund.