Vishcore Inc. vishcore.

pre-discovery worksheet

Eight prompts to answer before the first call.

Fill it out on paper or in a PDF annotator. It speeds up the fit-check conversation and keeps the first message free of secrets. Send the email template on start discovery when you're ready — the worksheet is for your team, not a submission form.

vishcore [pre-discovery worksheet]

client@discovery:~$ vishcore worksheet --prepare-fit-check

pressure point, cloud scope, regions, timeline

Terraform reality, stakeholders, known risks

no secrets, account IDs, ARNs, or credentials

  1. 01

    Pressure point

    What is forcing this conversation now?

    Examples: SOC 2 deadline, enterprise security review, buyer-blocker, internal incident, disaster recovery gap, Terraform drift.

  2. 02

    Cloud provider and account scope

    Which cloud provider, and what is the rough account scope across production accounts, projects, or subscriptions?

    A short phrase like “AWS · 3 production accounts · 1 staging” is enough. Do not write account IDs or ARNs.

  3. 03

    Regions and data residency

    Where does production traffic and customer data live today?

    Region names or a residency posture (“US-only”, “EU + US”) — no resource identifiers.

  4. 04

    Terraform or source-of-truth state

    How much of the current cloud is reflected in Terraform or another IaC system?

    Trusted, partial, stale, missing, or unknown. Pick the honest answer.

  5. 05

    Timeline

    When does this need to be in a defensible state?

    Audit date, buyer-review date, board cycle, or “no hard deadline yet”.

  6. 06

    Stakeholders and decision owners

    Who signs off on AWS access, scope, and remediation rollout?

    Roles, not names. Examples: CTO, Head of Security, AWS account owner, security partner.

  7. 07

    Known risks

    What do you already suspect is broken, missing, or undocumented?

    Plain language is fine. Skip security-group IDs, ARNs, and resource identifiers.

  8. 08

    What NOT to send in the first message

    Do not include secrets, passwords, tokens, access keys, account IDs, ARNs, IP allowlists, customer data, or production credentials. The fit check and scoping conversation happen before any AWS access is granted.