[ MSP.DD ] For investors · Updated
How do you check key-person risk in a startup's codebase?
Short answer
Look at who wrote and changed the core of the system over the last year. If one person authored most of the critical code and nobody else has touched it, the company depends on that person, whatever the org chart says.
Why it matters
Small teams often rely on one engineer for the hardest parts. If that person leaves after the deal, delivery slows and risk rises. AI-written code can make this worse when nobody fully understands what was generated.
How to check
- 01Map commit authorship per module over the last 12 months.
- 02Identify modules with a single active contributor.
- 03Check the tests and documentation for those modules.
- 04Ask who could take over each core part tomorrow, then check the history for evidence.
Red flags
- One person wrote most of the core and holds the only production access.
- Core modules with no tests and no documentation.
Good signs
- At least two active contributors on every core module.
- Runbooks and architecture notes that match the code.