Skip to main content
22
repositories mapped and classified
15 of 22
authored mainly by one departed engineer
28
continuity and risk items driving remediation
1
credential between a finished product and launch

Client: An AI code-generation company — a flagship code-generating monorepo plus 22 repositories covering a bespoke AI language, an event-mesh design, and several generated products. Much of the intellectual property was written by a single lead engineer, working with an AI coding agent, who then left the company.

The challenge

A textbook bus-factor-of-one crisis. The departed engineer was the main or only author of 15 of the 22 repositories, including the core generation engine. More than 1,500 commits came from an AI coding agent under his direction; documentation was thin and naming opaque. Nobody else understood the platform, it was impossible to tell novel IP from plumbing, generated output, and throwaway demos, and day-to-day operations depended on access and secrets he personally held.

What we did

We delivered a complete engineering-continuity package, checked against the live cloud tenant:

  • An IP map ranking all 22 repositories by IP value, maturity, and authorship, separating defensible core IP from regenerable output and stubs.
  • Platform architecture documentation rebuilt from the code, plus a deep-dive for every repository.
  • A 28-item continuity and risk register driving access revocation, credential rotation, and recoverability.
  • A read-only infrastructure audit that established ground truth — including that “production” was a naming convention, not an actual environment.
  • A calibrated reality check: roughly one-third of the platform’s vision was production-real, one-third early, and one-third aspirational.

The highest-leverage finding was almost anticlimactic. The company’s stalled commercial launch had been fully built weeks earlier but never shipped, because a single deploy credential had expired. We turned a presumed product problem into a one-credential deploy recovery, moved code signing to a secretless model, and fixed two build-blocking defects.

Results

“The code was never the risk. The risk is operational.”

An undocumented, AI-generated, single-author estate became a documented, classified, and recoverable portfolio — with the defensible IP identified and protected, a prioritized remediation roadmap, an onboarding path for the next engineer, and a revenue launch shown to be one credential away from live.

The client's identity is anonymized. The environment, findings, and results are drawn from a real Hat Boy Software engagement; figures are representative and rounded.

More case studies

Not sure where to start? Start with an assessment.

A senior review of your app, cloud estate, or AI platform, scoped and quoted before work starts, that ends in a prioritized plan, so you decide what to fix and when.

Talk to an engineer