Specialised Assessment · Commissioned Research
Commissioned Assessment

Stack Exposure & Dependency
Assessments

Operational Clarity produces independent Stack Exposure & Dependency Assessments for organisations seeking an evidence-based understanding of the software platforms they depend upon and how those dependencies interact.

Enterprise software dependency rarely exists in isolation. Identity systems, cloud platforms, business applications, integrations and administrative permissions create relationships that are difficult to understand by examining each product separately.

This assessment is a specialised application of the Structural Dependency Assessment methodology. It examines those relationships, the changes that may affect them, and the evidence available to support each finding. It is not an automated tool, vulnerability scanner, certification service, vendor ranking or software recommendation.

Section 02 — Application

When an Assessment May Be Useful

Possible applications include:

01

Technology or architecture reviews

02

Major software changes, renewals or migrations

03

Concerns about dependency concentration

04

Exit planning for a platform or provider

05

Acquisitions, mergers or divestments

06

Preparation for management or board review

Section 03 — Scope

Assessment Scope

Each assessment examines an agreed selection of software platforms and the organisational dependencies relevant to them.

Scope and depth depend on the evidence available and the organisation's requirements. Platforms, integrations and questions are agreed before research begins.

Section 04 — Research

Research Foundations

Assessments may draw upon the following independent research resources. These are research sources consulted by Operational Clarity, not automatically connected data feeds.

R/01

SoftTech Reviews

Independent vendor research, including Risk, Exit, Integration and Evidence profiles for individual software platforms.

R/02

SoftTech AI Registry

Where relevant, research into documented AI capability authority, permissions, action boundaries and human-confirmation requirements.

R/03

Risk Change Log

Historical record of changes to published vendor research, which can help show how documented characteristics have shifted over time.

Section 05 — Evidence

Evidence Distinctions

Every report separates four categories of information. Vendor documentation describes what a platform can do; it does not establish that an organisation has enabled a particular feature or integration.

E/01

Documented vendor characteristics

What published vendor research and documentation describe about a platform's capabilities, integrations and controls.

E/02

Customer-confirmed configurations and dependencies

What the organisation has confirmed about how a platform is actually configured, connected and used.

E/03

Potential dependencies requiring verification

Relationships that appear likely from the evidence available but have not yet been confirmed by the organisation.

E/04

Evidence gaps and matters not established

Questions the available evidence cannot answer, recorded openly rather than filled with assumption.

Section 06 — Output

What the Report Provides

An independent analytical report. It does not include numerical scores, vendor rankings, compliance certification or any guarantee of risk reduction.

01

Agreed assessment scope

02

Identified dependencies

03

Supporting evidence

04

Relevant limitations

05

Unresolved questions

06

Findings appropriate to the investigation

Where supported by the evidence and agreed scope, findings explain the significance of identified dependencies, including their potential consequences for operational continuity, concentration, integration exposure and reversibility.

Section 07 — Coverage

Additional Vendor Research

Organisations may enquire about commissioned independent research into platforms not currently covered.

Any such work requires its own scope, feasibility and evidence review. Findings are not predetermined.

Section 08 — Over Time

Periodic Review

Periodic reassessment of documented dependencies and material changes may be commissioned separately.

This is scheduled, scoped review work. It is not continuous surveillance, real-time alerting or automated monitoring.

Section 09 — Contact

Request Information.

Operational Clarity undertakes independent Stack Exposure & Dependency Assessments for organisations requiring an evidence-based understanding of software dependency, concentration, integration exposure and reversibility. Enquiries are welcome about assessment scope, available research coverage and commissioned reporting.