Skip to content
WGO
Open source · Runs on Codex or Claude

Evidence-led audits for startups and SMBs

Find out what is true, what is risky, and what needs to happen next. WGO turns scattered project evidence into decision-useful findings and safe next steps — with no hosted service, no database, and no dashboard.

Free and open source. Your code and evidence stay on your machine.

bash

$ git clone https://github.com/wgo-audit/code.git
$ cd code && ./install.sh ~/your-project
# then, in Codex or Claude:
› /wgo_onboard

How it works

From a plain-language concern to decisions you can act on

The audit scope follows the decision you need to make — not a fixed technical checklist.

  1. 01

    Business concern

    A question, risk, or opportunity you need clarity on. WGO scopes the audit around the decision leadership actually needs to make.

  2. 02

    Relevant perspectives

    It recommends the product, technical, operational, security, continuity, and business lenses that fit — and explains what it leaves out.

  3. 03

    Evidence

    It collects and verifies evidence from code, docs, repository history, and operations. Missing evidence is treated as evidence, not guessed around.

  4. 04

    Decision-useful insights

    Findings that change a decision, priority, sequence, or claim — each stating its confidence, cutoff, and limitations.

  5. 05

    Next moves

    Decide now on what is known, request the evidence to close key gaps, and correct issues at the source — with a 30–90 day plan.

What makes it different

Not another static analyzer

WGO is a semi-structured audit lead: it asks the right questions, inspects the right evidence, preserves uncertainty, and explains the result clearly.

Start with the business concern

Scope follows the decision leadership needs to make, not a fixed technical template.

Treat missing evidence as evidence

Inaccessible sources are reported as limitations, never quietly replaced by weaker proxies.

Separate facts from conclusions

Source evidence, observations, approvals, unknowns, and future work stay distinct and linked.

Ask questions that can change the answer

Material gaps become focused stakeholder questions or verifications. WGO does not guess intent.

Reconcile contradictions

Each reviewer surfaces meaningful conflicts, and synthesis reconciles them again across the whole audit.

Write for the people doing the work

Business owners, product managers, and technical leads each receive a report shaped around their responsibilities.

Facts, unknowns, and conflicts stay distinct

One never silently becomes another. Every material finding cites exact evidence and states its confidence and cutoff.

Facts

Verified and supported by evidence you can trace to its source.

Unknowns

Missing or unverified — named plainly, never filled with confident prose.

Conflicts

Differing or contradictory signals, surfaced and then reconciled.

Perspectives

Eleven reviewers, each answering one question

Start with the reviewers that answer your concern. Each is independent and can evolve without changing the others.

business-continuity

Business continuity

Can the company demo, deploy, operate, recover, and transfer control if a person, vendor, account, or environment disappears?

maintenance-cost

Maintenance cost

What skill mix, effort, operating burden, and change risk will a small replacement team face?

product-value

Product value

What customer and business value is demonstrably implemented, partial, promised, or still awaiting sign-off?

security-privacy

Security & privacy

What material identity, credential-sharing, exposure, privacy, PII, and operating-control risks exist?

revenue-risk

Revenue risk

What could interrupt demos, sales, pilots, onboarding, renewals, trust, or customer delivery?

expense-exposure

Expense exposure

What actual or potential cash exposure comes from infrastructure, software, staffing, commitments, and failure modes?

contributor-vendor-value

Contributor & vendor value

What usable output, ownership, knowledge, handoff, and cost-relative value did people or vendors provide?

project-health

Project health

Can a small team understand, prioritize, review, accept, release, and learn from the work?

scalability

Scalability

Does the product support its realistic business growth envelope across workload, data, operations, third parties, and cost?

code-quality

Code quality

Which code-level risks materially affect correctness, delivery, maintainability, security, or product promises?

architecture

Architecture

Is the current system, its dependencies, ownership, and important decisions understood well enough for safe change?

Each reviewer is independent and auditor-approved. See all reviewers →

“Small companies deserve rigorous answers without enterprise ceremony.”

WGO keeps the jargon under the hood, asks humans only the questions that matter, and refuses to turn missing proof into confident prose. The goal is not to produce the largest audit — it is to leave founders and operators with a trustworthy understanding of what is going on.

Find out what's going on.

Install WGO and run your first audit in minutes. It is open source and runs locally on Codex or Claude.

git clone https://github.com/wgo-audit/code.git