Symphony Apps Development logo — teal interlocking S monogram beside the studio wordmark
All writing

The audit we run on our own projects every quarter

We turned the checklist we use when reviewing other teams' systems inward, on our own delivered work, and found exactly the kind of drift we warn clients about.

Category
Process
Reading time
6 min
Published
14 Jul 2026
Topics
Process, Quality, Engineering

We are regularly asked to audit systems other teams built, and it took longer than it should have to apply the same list to our own delivered projects rather than assuming our standards at handover still held a year later.

What the audit covers

  • Backup restore, actually tested, not just configured, within the last quarter.
  • Dependency currency — how far behind the latest security patches the project's dependencies have drifted, and why, if the answer is more than a few weeks.
  • The bus factor — how many people currently understand the parts of the system that would be hardest to recover if the one person who built them left.
  • Monitoring that still points at someone — alerts that fire into a channel nobody reads any more, or to an account that left the client's business six months ago.
  • Cost drift on anything metered, particularly model API usage, which has a way of growing quietly as usage patterns shift after launch.

What we found the first time we ran it

On our own past projects: two with monitoring alerts routed to accounts that no longer existed, one with a restore process that had never actually been executed despite being "configured", and one with a model-backed feature whose per-operation cost had roughly tripled since launch because usage patterns had shifted in a way nobody was watching for.

The audit we sell to clients is not a courtesy. Running it on our own work found problems we would have criticised someone else for.

Why this drifts even on projects we control

Attention naturally moves to the newest engagement. A project that shipped well and has not generated a support ticket in months gets no attention at all, which is precisely the condition under which monitoring goes stale and nobody notices.

What changed as a result

Every project we deliver now gets a calendar entry for a quarterly check, owned by a named person, with the same checklist we would use auditing an outside client's system. It is a small amount of overhead against every engagement and it has already caught a live monitoring gap before it became an incident, which paid for the practice on its own.

The uncomfortable part

Several of the gaps we found were on projects we would have described, if asked casually, as "in good shape". That gap between casual confidence and an actual check is the entire reason the audit exists for other people's systems, and there was no good argument for exempting our own.

Tell us what you’re trying to ship

A first call is thirty minutes and costs nothing. Bring the problem, not a spec — working out what to build is the part we are good at.

Or email office@symphonyapps.ro. We reply within one business day, in English or Romanian.