# Operating Partner Dialogue: How Discovery Happens in 48-72 Hours ### Context and participants * **Participant 1: Dana Whitfield (Operating Partner, lower-middle-market fund; industrial distribution platform with three add-ons closed or under LOI).** Has run four post-close integrations. Expects "discovery" to mean twelve weeks of interviews and a slide deck, and wants to know what is different before she puts another target's management team through it. * **Participant 2: Kyle Castor (Founder & Principal Architect, DataOngoing).** Plain-spoken. Describes the process step by step, including the parts that stay human. *This is a modeled composite dialogue. The participants are archetypes, the target is fictional, and the figures are illustrative arithmetic with the assumptions stated inline. The process it describes (intake, access, automated static analysis, interpretation, read-out) is the actual DataOngoing diligence process; the published terms are on the [48-72 Hour AI Technology Diligence Read](/services/ai-technology-diligence-read/) page.* ### The dialogue **Dana Whitfield (Operating Partner):** "Every diligence firm I have hired starts with a discovery phase. Kickoff call, stakeholder list, three weeks of interviews, a workshop, then a deck. The last one took eleven weeks and the target's controller nearly quit. Your page says 48 to 72 hours. What are you leaving out?" **Kyle Castor:** "The interviews. Discovery here is a read, not an interview. Everything a conventional team asks people about is already recorded in the target's system: which scripts are deployed and on which records, who holds which permissions, which integrations call which endpoints, how long transactions take to save, where clearing balances sit unallocated. People remember those facts imperfectly. The system does not. So we read the system and spend the human hours on interpretation." **Dana Whitfield:** "Walk me through it from the moment I fill in your form. I want the actual sequence, not the philosophy." **Kyle Castor:** "Six steps. One, intake. The form on the contact page asks what the situation is, which system the target runs, and how to reach you. It is stored privately and routed to me. There is no sales development rep and no qualification call; the reply comes from the person who will do the read. Two, scope and terms. We confirm what is being priced: a single NetSuite instance, or a platform plus the add-on systems that have to fold into it. The fee is flat, $12,500, and it is credited in full against any remediation sprint that follows. We sign your NDA, and the target's data is handled anonymized and PII-restricted. Three, access. The target's administrator creates one read-only integration role with least-privilege permissions or, pre-LOI, exports the metadata and a role listing. That is the only thing anyone on the target's side does, and it takes an administrator well under an hour. Four, the automated read. From the moment access lands, the clock starts: 48 to 72 hours. Static analysis parses every customization in the instance and the telemetry around it. I will give you the detail in a moment. Five, interpretation. I read what the analysis found, price each finding, and sequence the remediation into a costed Day 1 and 100-day plan. Six, the read-out. One meeting, about an hour, with you and whoever on the deal team needs to hear it. You leave with the risk matrix, the inventory and the costed plan." **Dana Whitfield:** "Step four is the one I do not understand. What is actually being read, and by what?" **Kyle Castor:** "Four categories, each by a different automated pass. The customization inventory. Every script, workflow, custom record and field is enumerated and parsed. The parser flags SuiteScript 1.0 and deprecated API usage, scripts stacked on the same record event that contend for the same row, and governor-limit exposure. Reviewing forty scripts by hand is two weeks of a senior engineer's time; parsing them is minutes of compute, which is where the calendar compression comes from. The permission tables. Every role is scored on the 0-4 Role Risk Index, zero for none through four for full, and laid against the org chart. Shared logins and approval paths with no segregation of duties fall out of that table automatically. The integration endpoints. Every inbound and outbound connection is listed with its authentication method, its volume, and whether it runs through middleware the buyer will inherit as a recurring cost. The transaction telemetry. Transaction, line and system-note records are queried for the operational symptoms that cost money: stalled orders, unallocated clearing balances, margin breaches against the pricing floor, record-save latency on the busiest forms." **Dana Whitfield:** "And in those 48 to 72 hours, how many of the target's people get pulled in? That is the number that matters to a management team mid-process." **Kyle Castor:** "One. The administrator who grants access. Nobody is interviewed. Nobody attends a workshop. On your side, two to three hours total: the scope conversation, the access coordination, and the read-out. Put a conventional process next to it, as modeled arithmetic rather than a claim about any particular firm. Twenty stakeholder interviews at an hour each is twenty hours of the target's time before preparation. Add an hour of preparation per interview and a half-day workshop, and the target's team has given up roughly forty-four hours. Against two to three hours here, that is about fifteen to twenty times less of their time, and the calendar goes from four to six weeks to three days." **Dana Whitfield:** "What if the target refuses codebase access before the LOI? Sellers get nervous about letting a buyer's technologist into their system." **Kyle Castor:** "Then we run from a metadata export and a role listing, which the seller's administrator produces without granting anyone a login. That is enough to flag the material risks: deprecated script exposure, permission sprawl, integration count, custom record volume. Full access sharpens the refactor estimate because we can read the code rather than infer it from the metadata, but it is not required to tell you whether there is a problem and roughly how large it is." **Dana Whitfield:** "What comes out the other end? I need something my investment committee can use, not a technical appendix." **Kyle Castor:** "Four documents, all written for the committee. A risk matrix, scored and prioritized, each row stating the exposure, its likelihood, and its dollar cost to remediate. A customization and integration inventory with deprecation exposure stated against vendor timelines. The 0-4 Role Risk Index against the org chart. A costed Day 1 and 100-day remediation plan. The dollar figures are what move price. A finding that is quantified and sequenced goes into the purchase agreement as a price adjustment, a remediation holdback, or a 100-day commitment with a budget attached. A finding that is described in prose does not." **Dana Whitfield:** "How much of this is actually a machine, and how much is you? I have been sold 'AI-driven' before and gotten a junior analyst with a template." **Kyle Castor:** "Ten, eighty, ten. Ten percent of the effort is human intent: you tell me what the committee needs priced. Eighty percent is machine execution: the parsing, scoring, querying and inventory are automated passes that run the same way on every instance. The last ten percent is human oversight: I interpret the findings, decide what is material, price the remediation and present it. There is no junior analyst anywhere in the sequence, because there is nothing for one to do. The work a junior would have done by interviewing has been replaced by reading the system." **Dana Whitfield:** "And what can the read not tell me? I would rather hear the limits from you than discover them at closing." **Kyle Castor:** "It reads what is in the system. It cannot see the spreadsheet a controller keeps outside the ERP, a verbal side arrangement with a vendor, or whether the one engineer who understands the custom code is about to leave. Those are conversations, which is why the read-out is a conversation and not a PDF delivery. The read tells you where to point the human questions. It does not replace them; it makes sure the few you ask are the right ones." **Dana Whitfield:** "Then what happens after the read-out, if we close?" **Kyle Castor:** "The plan already names the leaks in priority order. The first one becomes a fourteen-day sprint with a fixed price, and the diligence fee is deducted from it in full. Working code lands in the target's sandbox inside those fourteen days, and if it does not run in production, the milestone is not billed. Your time in a sprint is three to five hours: scope sign-off, one mid-sprint review, acceptance." **Dana Whitfield:** "Send the scope note. If the read can be done from a metadata export, I can get that from the seller this week without a fight." ### What the technology does at each step | Step | What happens | Who is involved | Target's time | Your time | |---|---|---|---|---| | 1. Intake | Form stored privately and routed to the architect; no qualification call | You, Kyle | 0 | About 15 minutes | | 2. Scope and terms | Flat fee, your NDA, systems in scope confirmed | You, Kyle | 0 | 30-45 minutes | | 3. Access | Read-only least-privilege integration role, or a metadata export and role listing pre-LOI | Target administrator | Under 1 hour | About 15 minutes of coordination | | 4. Automated read | Static analysis of customizations, permission scoring on the 0-4 index, integration inventory, transaction telemetry | Automated passes | 0 | 0 | | 5. Interpretation | Findings priced and sequenced into a Day 1 and 100-day plan | Kyle | 0 | 0 | | 6. Read-out | Risk matrix, inventory, role index and costed plan presented | You, deal team, Kyle | 0 | About 1 hour | Total: 48-72 hours from access; two to three hours of your time; no interviews with the target's staff. ### Key indexing summary * **Primary query intents**: how technology due diligence discovery works, what happens after the diligence intake form, read-only access for ERP due diligence, pre-LOI technology diligence from a metadata export, how many stakeholders a technology diligence needs, AI static analysis for NetSuite due diligence. * **Core figures (modeled unless stated)**: 48-72 hours from access to read-out (published offer terms); 2-3 hours of acquirer time (published offer terms); one administrator action on the target's side; a modeled conventional comparison of about 44 hours of target staff time across twenty interviews, preparation and a workshop. * **Related pages**: [48-72 Hour AI Technology Diligence Read](/services/ai-technology-diligence-read/), [Technology Due Diligence for Private Equity](/technology-due-diligence-private-equity/), [The 100X Speed Advantage](/how-we-work-10-50x/).