Why the clock is anchored to access and not to purchase
Because the version anchored to purchase will slip, and the first time it does it reads as a bait-and-switch rather than as a scheduling reality. The firm does not control how long it takes a client to get a security review done, find the person who administers the ticketing system, or schedule a kickoff across four calendars. It does control what happens once credentials exist.
So the commitment is made about the part that is controllable, and the uncontrollable part is stated as an estimate: five to ten days between commissioning and access, in most cases. A buyer who plans on twenty-five calendar days end to end will rarely be disappointed. A buyer who was told fourteen and got twenty-five has been misled, even if nobody intended it.
This also means there is one thing a client can do to compress the timeline that is worth more than everything else combined, and it is covered at the end.
What the ten days contain
It is a sequence rather than a schedule, and the distinction is deliberate. The order is inherent to the work and can be stated with confidence. A day-by-day timetable would be a commitment nobody agreed to, and the first time it slipped it would cost exactly the credibility the access anchor exists to protect.
- 01Access. Credentials are provisioned and the clock starts. Nothing before this point counts against the ten days.
- 02Instrumentation. Every path a lead can take through the systems gets traced, and the point where each one stops gets found. This is where most of the work happens and most of it is invisible from the client side, which is worth knowing in advance so the quiet week does not read as inactivity.
- 03Interviews. Four to six conversations, thirty minutes each, across sales, operations and service. No preparation is asked of anyone. The object is the gap between what the system records and what people actually do, and that gap is only ever found by talking to the people doing it.
- 04Quantification. Each leak is priced against the company’s own numbers, annualised, and ranked by recoverable dollars against the effort to recover. Anything that cannot be measured in a system the company owns does not go in the report.
- 05Readout. The report lands, then ninety minutes live with whoever the client wants in the room. Two weeks from access, end to end.
Why ten days is enough, when diligence normally takes longer
This is the fair objection, and the answer is pattern recognition rather than speed. A thousand client engagements have run through this firm since 2021. The same short list of operational failures turns up in almost every company, which means the work is not open-ended discovery — it is checking a known list against a specific estate, in a known order, starting with the failure that is most often the largest.
A diagnostic that started from first principles every time would take a quarter and would produce a worse answer, because it would spend its budget on breadth rather than on measuring the three things that matter in that particular company. The narrowness is the product.
What ten days is not enough for is anything requiring a measurement window. Response latency and conversion-by-latency are visible in twelve months of history that already exists. A recovery figure is not — that only becomes real after implementation, measured in the same system against the same baseline, which is why found and sealed are different words with different definitions.
The two things that cause almost every overrun
The first is access, and it is not close. Credentials, API keys, admin rights on a system nobody currently owns, a third-party vendor who takes eleven days to answer an integration request. This delays more engagements than any analytical problem and it is almost entirely preventable by starting the requests the day the engagement is commissioned rather than the day before kickoff.
The second is the absence of a single owner. One person who can grant access and answer questions without escalating is a stated requirement of the engagement, and where that person does not exist the work stalls in a way no amount of effort on the firm’s side fixes. An engagement sponsored by a committee spends its first week finding out who decides.
What a client can do before kickoff to compress it
- Name the owner first, before anything else. Not the team — the person, with the authority to grant access without going upward.
- List every system that touches a lead, and name who administers each one. Start the access requests immediately, in parallel, rather than as each is needed.
- Get the security review started on day one if one is required. This is the single longest pole in most mid-market engagements and it is entirely parallelisable.
- Book the four to six interview slots in advance. Thirty minutes each, across sales, operations and service. Half of scheduling friction is calendars, not willingness.
- Do not assemble anything. Twelve months of whatever the systems already hold is the input. Time spent preparing a data pack is time the firm would rather you spent finding the admin credentials, and a hand-assembled export is less trustworthy than the raw system anyway.
What a shorter quote usually means
A three-day diagnostic is a workshop. That can be genuinely useful — a structured conversation with an experienced operator often surfaces the obvious leak — but it produces hypotheses rather than figures, because there is no time to measure anything in a system. If what you need is a number you can put in front of a board, a workshop will not produce one.
Conversely, a twelve-week engagement at this scope is usually being staffed rather than scoped: the timeline is a function of how many people are being kept billable, not of how long the work takes. The tell is whether the fee is fixed. A fixed fee makes a long timeline expensive for the firm, which is the alignment you want.