File 04
The nine-phase audit
Preflight resolves the scope contract and the ledgers. Then nine phases, each with its own questions, method, required controls and deliverables. A phase is complete, N/A with a reason, unknown with the evidence named, or blocked by a control.
Stage
Preflight
- Complete the scope contract.
- Resolve the organization, executive, and region.
- Identify applicable privacy, outreach, and source-use rules.
- Set passive-only as the default authorization.
- Choose audit mode and time box.
- Create source, claim, calculation, opportunity, and contact ledgers.
- Define the three decisions the audit must improve.
Source: file 04 · preflight · line 3
Phase 1
Technical and passive OSINT fingerprint
Minimum output: resolved asset map, passive signals, security unknowns, executive stated priorities
questions
- What official domains, subdomains, certificates, public services, repositories, documents, vendors, and technology signals are observable?
- Which signals indicate complexity, aging, inconsistency, or missing controls without requiring active testing?
- Which findings are verified facts, passive hints, or unknown?
- What business outcome could the technical condition affect?
collection lanes
- official domains, DNS, RDAP/WHOIS and certificate transparency;
- passive technology fingerprinting and historical snapshots;
- public status, security, privacy, trust, API and developer pages;
- public repositories and dependency manifests;
- public documents and metadata, collected under source terms;
- authorized breach-notification/domain-monitoring sources;
- executive speeches, filings, posts, interviews, board and association biographies.
required controls
- No port scanning, directory brute force, authentication attempts, exploit checks, or payloads.
- Do not infer MFA status.
- Do not collect credential material.
- Treat version fingerprints as unverified until corroborated.
- Separate target-owned assets from third-party/CDN/shared infrastructure.
deliverables
- asset and dependency map;
- technical-change timeline;
- evidence-safe risk register;
- business-mechanism hypotheses;
- private responsible-disclosure route for material security signals.
Source: file 04 · phase-1-technical-and-passive-osint-fingerprint · line 13
Phase 2
PR, brand sentiment, and reputation
Minimum output: sampling frame, SOV, themes/sentiment, response/narrative analysis
questions
- What themes recur, where, and over what window?
- Is the company responding? How quickly and consistently?
- Which narratives are customer misunderstandings, service failures, contested claims, or information gaps?
- Who owns share of voice by topic and outlet tier?
method
- declare sources, window, queries, languages, and sample denominator;
- collect platform-permitted records and RSS/news indexes;
- normalize entity, topic, stance target, sentiment, engagement, and response;
- deduplicate syndication and copied posts;
- human-code a stratified sample to test the classifier;
- compare target and competitors using identical rules;
- map narrative propagation using the fourteen change variables.
deliverables
- topic-by-source sentiment table;
- complaint/response matrix;
- earned-media and SOV benchmark;
- narrative risk/opportunity map;
- crisis-information gaps.
Source: file 04 · phase-2-pr-brand-sentiment-and-reputation · line 48
Phase 3
Marketing, advertising, and audience engagement
Minimum output: public ads, creative/offer, SEO/content, demand clusters, funnel hypotheses
questions
- What current creatives, promises, proof, formats, offers, and calls to action are visible?
- Where is high-intent demand not matched by a relevant page, ad, answer, or offer?
- Where does the journey lose clarity, trust, performance, accessibility, or message match?
- Which gaps are observable and which require internal analytics?
method
- inspect official ad-transparency libraries manually or through permitted interfaces;
- inventory target and competitor content over an equivalent window;
- group search demand into problems, comparisons, alternatives, costs, risk, implementation, and local intent;
- map each topic to journey stage and existing asset;
- test public pages for performance, accessibility, structured data, indexability, and broken flows without submitting forms;
- identify missing measurements that prevent CAC/conversion conclusions.
deliverables
- creative/message matrix;
- content velocity and topic-coverage matrix;
- demand-to-asset gap map;
- journey friction register;
- measurement plan.
Source: file 04 · phase-3-marketing-advertising-and-audience-engagement · line 75
Phase 4
Overlooked opportunities and blind spots
Generate across: Candidate families: Rank three levers for the executive brief, but preserve the full option register.
Minimum output: three ranked levers plus full alternative/elimination register
- unused owned/earned/paid/partner channels;
- under-monetized audiences, content, data, proof, expertise, integrations, or locations;
- missing follow-up, activation, expansion, referral, or win-back loops;
- regional listings, associations, events, awards, trade media, and co-marketing;
- operational assets that can become a productized diagnostic or trust signal;
- a new unit of value that creates a C4 demand curve.
Stakeholder × Job × Journey × Channel × Format × Offer × Geography × Time
× Ownership × Feedback × Five change states
Source: file 04 · phase-4-overlooked-opportunities-and-blind-spots · line 101
Phase 5
Microeconomic and unit-economic analysis
Minimum output: pricing, marginal cost, CAC/LTV, retention, vendor/supply input map
questions
- What price and packaging are public? What is genuinely comparable?
- Where might willingness-to-pay differ by segment or use case?
- Which manual or vendor-dependent steps raise marginal cost?
- Where might acquisition, activation, churn, support, or expansion leak contribution margin?
- What capacity constraint makes the next unit more expensive or slower?
required outputs
- unit-economics tree;
- public pricing comparison with scope/feature normalization;
- operational-friction hypotheses;
- LTV/CAC model template with missing inputs;
- low/base/high scenario ranges.
Source: file 04 · phase-5-microeconomic-and-unit-economic-analysis · line 121
Phase 6
Competitor benchmark and gap analysis
Required dimensions:
Minimum output: contract, selection/rejection, normalized target/comparator matrix
- select up to three comparable organizations with reasons, using fewer when comparability fails;
- freeze a common window, geography, customer, and offer class;
- compare facts separately from proxies;
- normalize features, price units, content counts, outlets, reviews, and delivery claims;
- identify target advantage, parity, disadvantage, and unknown;
- find whitespace—not just missing features.
- technology and delivery;
- offer, packaging, price and proof;
- discovery/content/ad presence;
- media SOV and narrative ownership;
- customer experience and response;
- operating/economic proxies;
- strategic trajectory across five LAKA change states.
Source: file 04 · phase-6-competitor-benchmark-and-gap-analysis · line 145
Phase 7
Macro and industry mapping
For each driver record: Driver families: Use primary statistical and regulatory sources. Do not turn national averages into company-specific impact without an exposure mechanism.
Minimum output: current drivers, transmission hypotheses, scenarios, regulatory register
- interest rates and credit;
- inflation, wages, productivity and labor availability;
- currency, trade, shipping, input costs and supply concentration;
- regulation, privacy, accessibility, security, sector rules and deadlines;
- demographic, geographic, technology and demand shifts;
- platform/API/policy dependencies;
- climate/energy exposure where material.
Driver → exposure path → affected unit → direction → magnitude range
→ lag → leading indicator → management lever → source
Source: file 04 · phase-7-macro-and-industry-mapping · line 164
Phase 8
Financial impact and dollar metrics
For every proposed number: The matrix includes not estimable when appropriate. It is better than a fabricated dollar value.
Minimum output: model/input ledger, ranges, sensitivity, overlap, not-estimable states
- identify observed/reported/measured/benchmark/assumed inputs;
- state formula and unit;
- calculate low/base/high;
- apply attribution and realization factors;
- state time-to-value, one-time cost, recurring cost, and risk;
- test overlap with other gaps to prevent double counting;
- show sensitivity and break-even;
- label scenario vs target-reported fact.
Source: file 04 · phase-8-financial-impact-and-dollar-metrics · line 185
Phase 9
Executive pitch and CRM output
Minimum output: eligibility gate, drafts, agenda, exact CRM view, governance fields
pitch selection
- evidence strength;
- relevance to the executive's public business remit;
- economic mechanism clarity;
- service fit;
- novelty without creepiness;
- reversible next step;
- low legal/reputation risk.
human approval
- correct company and person;
- current title;
- finding and source accuracy;
- no sensitive security or personal detail;
- no misleading subject line or certainty;
- applicable consent/identification/unsubscribe requirements;
- suppression and opt-out lists;
- appropriate send volume and channel.
Source: file 04 · phase-9-executive-pitch-and-crm-output · line 200
Stage
Final synthesis
The report contains seven user-facing sections: Appendices contain the evidence ledger, calculations, tool/source registry, full alternatives, limitations, and research backlog.
- Executive briefing and OSINT digest
- Marketing, PR and overlooked opportunities
- Micro- and macroeconomic diagnostic
- Competitor benchmark
- Financial impact matrix
- C-suite outreach blueprint
- CRM import table
Completeness
An audit is complete only when every one of these holds. Anything short of that is a partial audit that says so.
- every required nine-phase module is complete or carries a reasoned N/A/Unknown;
- all material findings are supported by evidence records;
- every critical feature or risk is checked against all fourteen change variables, with non-applicable variables explained;
- baseline, boundary, contradiction, and failure states have been tested;
- financial ranges reconcile and do not double count;
- competitor comparisons use like-for-like time windows and measures;
- personal and outreach data passes privacy, relevance, and consent/legitimate-use review;
- the executive brief states limitations and missing evidence.