Evidence-led audits for startups and SMBs
Find out what is true, what is risky, and what needs to happen next. WGO turns scattered project evidence into decision-useful findings and safe next steps — with no hosted service, no database, and no dashboard.
Free and open source. Your code and evidence stay on your machine.
$ git clone https://github.com/wgo-audit/code.git
$ cd code && ./install.sh ~/your-project
# then, in Codex or Claude:
› /wgo_onboardHow it works
From a plain-language concern to decisions you can act on
The audit scope follows the decision you need to make — not a fixed technical checklist.
-
01
Business concern
A question, risk, or opportunity you need clarity on. WGO scopes the audit around the decision leadership actually needs to make.
-
02
Relevant perspectives
It recommends the product, technical, operational, security, continuity, and business lenses that fit — and explains what it leaves out.
-
03
Evidence
It collects and verifies evidence from code, docs, repository history, and operations. Missing evidence is treated as evidence, not guessed around.
-
04
Decision-useful insights
Findings that change a decision, priority, sequence, or claim — each stating its confidence, cutoff, and limitations.
-
05
Next moves
Decide now on what is known, request the evidence to close key gaps, and correct issues at the source — with a 30–90 day plan.
What makes it different
Not another static analyzer
WGO is a semi-structured audit lead: it asks the right questions, inspects the right evidence, preserves uncertainty, and explains the result clearly.
Start with the business concern
Scope follows the decision leadership needs to make, not a fixed technical template.
Treat missing evidence as evidence
Inaccessible sources are reported as limitations, never quietly replaced by weaker proxies.
Separate facts from conclusions
Source evidence, observations, approvals, unknowns, and future work stay distinct and linked.
Ask questions that can change the answer
Material gaps become focused stakeholder questions or verifications. WGO does not guess intent.
Reconcile contradictions
Each reviewer surfaces meaningful conflicts, and synthesis reconciles them again across the whole audit.
Write for the people doing the work
Business owners, product managers, and technical leads each receive a report shaped around their responsibilities.
Facts, unknowns, and conflicts stay distinct
One never silently becomes another. Every material finding cites exact evidence and states its confidence and cutoff.
Facts
Verified and supported by evidence you can trace to its source.
Unknowns
Missing or unverified — named plainly, never filled with confident prose.
Conflicts
Differing or contradictory signals, surfaced and then reconciled.
Perspectives
Eleven reviewers, each answering one question
Start with the reviewers that answer your concern. Each is independent and can evolve without changing the others.
business-continuity
Business continuity
Can the company demo, deploy, operate, recover, and transfer control if a person, vendor, account, or environment disappears?
maintenance-cost
Maintenance cost
What skill mix, effort, operating burden, and change risk will a small replacement team face?
product-value
Product value
What customer and business value is demonstrably implemented, partial, promised, or still awaiting sign-off?
security-privacy
Security & privacy
What material identity, credential-sharing, exposure, privacy, PII, and operating-control risks exist?
revenue-risk
Revenue risk
What could interrupt demos, sales, pilots, onboarding, renewals, trust, or customer delivery?
expense-exposure
Expense exposure
What actual or potential cash exposure comes from infrastructure, software, staffing, commitments, and failure modes?
contributor-vendor-value
Contributor & vendor value
What usable output, ownership, knowledge, handoff, and cost-relative value did people or vendors provide?
project-health
Project health
Can a small team understand, prioritize, review, accept, release, and learn from the work?
scalability
Scalability
Does the product support its realistic business growth envelope across workload, data, operations, third parties, and cost?
code-quality
Code quality
Which code-level risks materially affect correctness, delivery, maintainability, security, or product promises?
architecture
Architecture
Is the current system, its dependencies, ownership, and important decisions understood well enough for safe change?
Each reviewer is independent and auditor-approved. See all reviewers →
“Small companies deserve rigorous answers without enterprise ceremony.”
WGO keeps the jargon under the hood, asks humans only the questions that matter, and refuses to turn missing proof into confident prose. The goal is not to produce the largest audit — it is to leave founders and operators with a trustworthy understanding of what is going on.
Find out what's going on.
Install WGO and run your first audit in minutes. It is open source and runs locally on Codex or Claude.
git clone https://github.com/wgo-audit/code.git