Blog

Discovery worth the name: evidence over workshops

Most programme discovery is a series of workshops and a questionnaire. It captures what people remember, not what exists. The gap between the two is where migrations go wrong, and it is entirely avoidable.

Discovery as it is usually done

Ask a partner what their discovery phase involves and you will usually hear the same answer: stakeholder workshops, application-owner questionnaires, and a spreadsheet circulated for comment. Weeks of calendar time, a deck at the end, and a scope built on whatever the people in the room could recall.

The problem is not effort or good faith. It is that human memory is the wrong instrument. The engineers who built the estate left years ago. The application owner list is a snapshot of an org chart from two restructures back. Nobody remembers the logon script that maps a drive for one department, or the Group Policy Object that was “temporary” in 2016. Workshops surface the estate people carry in their heads. The estate on the wire is a different thing entirely.

Read the estate, not the room

Real discovery interrogates what actually exists. Every Group Policy Object, its every setting, where it links and what it filters. Every application that is installed, and, separately, every application that is actually launched, because those are very different lists. Device hardware and readiness. Shares, printers, drive mappings, scheduled tasks, the configuration debris that twenty years of administration leaves behind.

This is why we built Scout, our discovery capture tool, and why we run it before we let anyone near a scope document. It reads the estate directly and returns structured evidence: not “we believe there are around 40 GPOs”, but the precise object count, every setting inside them, and the usage data that says which of them still matter.

Workshops surface the estate people carry in their heads. The estate on the wire is a different thing entirely.

Recall versus reality

The gap between what people remember and what capture finds is not a rounding error. It changes scope decisions. In one enterprise engagement, a raw inventory of 26,000 application titles rationalised down to about 1,000 that the business genuinely needed: a result no questionnaire would ever have produced, because no set of humans held that picture. The same pattern repeats at every layer. Applications everyone swears are critical that telemetry shows nobody has opened in six months. Applications nobody named in any workshop that hundreds of people use daily. Settings estates several times larger than anyone believed, and dependencies that only show up when you read the actual policy, not the folklore about it.

Each of those findings moves money and risk. Packaging effort, licensing, testing scope, migration sequencing and timeline all key off the application and settings inventory. If that inventory is recall-based, every downstream number inherits its error. With Windows 10 support ended last October and Extended Security Updates a paid bridge that runs out, estates paying for time cannot afford to spend it migrating things that do not exist and missing things that do.

Read-only, and nothing leaves

The usual objection to estate-level capture is security, and it deserves a serious answer rather than reassurance. Ours is architectural. Capture runs read-only: it changes nothing, installs no agents and leaves no footprint. And it runs with zero network egress: nothing is transmitted off your network by the tool, and the captured output is a file your own team reviews and hands over. A discovery exercise that demands standing network access to your domain controllers, or streams your configuration to someone else's cloud, has already failed its own risk assessment.

What to demand from any partner's discovery

Whether you work with us or anyone else, hold discovery to three tests. First, you keep the evidence. The raw capture belongs to you, in a form your own engineers can open and query, not summarised beyond recognition in a slide. Second, insist on an exclusions register: an explicit record of what was deliberately not captured or not assessed, and why. What a discovery admits it skipped tells you more about its rigour than what it includes. Third, traceability. Every scope decision, every “retire”, “replace” or “migrate”, should cite the captured fact that justifies it. If a partner cannot show the evidence behind a decision, what you have is an opinion with a project plan attached.

Workshops still have a place: for intent, priorities and appetite for change. But they are where discovery ends, interpreting the evidence, not where it starts. If your current discovery would collapse the moment someone asked “show me the data behind that”, it is not discovery. It is a survey.

Ready for discovery you can defend?

Our evidence-based discovery reads your estate read-only, with zero egress, and hands you the proof behind every scope decision.