31 PRs closed this quarter without ever merging - paid for, shipped nowhere.
Your engineering org is a black box. We turn the lights on.
Every expensive problem in your org - the problems, the price, the fix.
- Sweep the closed-unmerged 31 - decide early, cut the write-offs.
- Second owner onto payments.
See what we’d find in yours.
The scoreboard, the money already sunk, the risk if you ignore it - every number with a receipt.
Overview
Your Company · 34 developers · 5 of 8 organs measured
Your Company grades C - two expensive things, one bright spot.
payments has exactly one living maintainer.
Small PRs, shipped clean - median PR under 180 lines, four weeks running.
3 reviewers approve 78% of merges - the real bus factor is your merge gate, not the authors.
Review eats 46% of delivery time - PRs wait a median 12h for first eyes.
~31% of merged lines look AI-assisted - a disclosed estimate, never a verdict on anyone.
You ship 4×/week - but recovery drags: median time-to-restore sits at 9h.
62% of build time went to keeping the lights on - not new value.
Half your highest-traffic modules have no living doc - onboarding pays the tax.
It takes 2 people not showing up and 8 of your areas go orphan.
Cross-train the eight single-owner areas before a holiday turns into an incident.
Six truths you can’t see today.
Counted from your own repos - sunk money, hard risk, receipts. Live on your data in minutes.
Where the weeks actually die.
The stage eating your cycle time - named, with the slow PRs as receipts. Pickup, review, merge, deploy: we tell you which one is costing you the week, in hours.
The work that shipped nowhere.
Closed-unmerged and stalled PRs - payroll demonstrably spent, delivered never. Counted from your repos, priced at your cost model.
The invoice for ignoring it.
One-owner areas, the fire drill, and the rebuild bill if the owner walks - with the seconding plan, not just the scare.
Who’s carrying it - and who’s drowning.
Load, coasting, judged overwork - guarded and receipt-backed. Never a shame board.
Is the AI spend even landing?
Adoption, landing rate - and the paid seats nobody uses. Subscription cash, not vibes.
You paid for this twice.
The same files fixed, re-fixed, and fixed again - rework counted from your own commits, with the second bill attached.
Count the strangers who can publish into your build.
Drop a lockfile. Ten seconds later you have the packages a single account can ship straight into your next install, and how far each one reaches.
Drop one of these here
- package-lock.json
- pnpm-lock.yaml
- go.mod
- Cargo.lock
- Gemfile.lock
- composer.lock
Parsed in memory, then gone. There is no database column that could hold your file.
5 of 18 dependencies can be published by a single account.
zod975M downloads/30done account can publish it@types/react559.2Mone account (DefinitelyTyped)@types/react-dom455.7Mthe same accountbcryptjs49.7Mone accountpostgres48.7Mone account
Run 2026-07-29. None of those accounts are on that team’s payroll - and in 2024 one trusted maintainer account shipped a backdoor into xz (CVE-2024-3094).
Watches the whole payroll.
Costs a rounding error of it.
1% recovered is the floor, not the promise - itemized on the right, receipts attached.
Do the math on your own org
Recover just 1% of that engineering + AI spend - a fraction of what the product itemizes - and it has paid for itself 3.8× over. 1% is the floor, not the promise. We don’t promise a percentage - we show you exactly where a much bigger one is leaking, receipts attached. You do the math.
Per seat, against the category: a comparable tool at this headcount (~€22/dev/mo - a published rate in this category, and the cheaper end of that vendor’s own list) runs €330/mo. Busfactor Pro is €20/dev/mo on annual billing, so the same team costs €300/mo - that’s €30/mo you keep. No seat cap, and every tier runs the same product.
Kill work that’s already dead
Zombie PRs and stale WIP - paid-for work rotting in a branch.
Fix the stage that eats lead time
Pickup, review, merge, or deploy - the real bottleneck named.
De-risk the one-person areas
Two people out, eight areas orphan. A pairing plan before it costs you.
Point the payroll at the roadmap
New vs improvements vs KTLO vs unplanned - judged against healthy ranges, priced.
Verify the AI line item
AI-assisted work tracked to merge. Renew the seats that land.
Get a firm grip on your engineering org.
Two dozen surfaces on one deterministic engine - browse the full feature catalog →
The real thing runs on your own repos, tickets, and incidents.
Overview
The 60-second health read - one index, four judged sub-scores.
Stories
Every finding is a card: the headline, both readings, the fix - praise gets its own.
Metrics
Not a wall of numbers - each stat graded against expert bands: healthy, watch, or bad.
Industry benchmarks
Judged against published research - DORA, LinearB, GitClear - cited and honestly labeled “not your peers”, never invented. When enough orgs opt in, the same band silently sharpens to your anonymized peer cohort - never an empty “not enough peers” state.
Data honesty
Force-push detection quarantines the commits a rebase erased, canonical identity stops one human counting as four, and a stale sync says so - the tool that tells you when its own data is dirty.
MCP server
Query your engineering data from Claude, Cursor, or any MCP client - and every number in the answer is quoted from your data, read-only. Busfactor runs no model of its own, so the tool can only hand over figures your data already contains. Your AI client still writes the sentence around them: safer by construction, not magic.
Flow
Where the weeks go - pickup, review, merge, deploy, with the stage that eats lead time.
Delivery forecast
A completion range (p50-p90) quoted from your own weekly throughput - not a black-box Monte-Carlo - that ends in a door: the ONE delivery stage that, if you speed it up, pulls the date in. LinearB predicts a date; we predict a date and hand you the lever.
Initiative tracking
Track a business initiative across teams - progress counted from your own linked tickets (never the tracker’s %), the teams involved, and an on-track-vs-target read from your real throughput. Drawn on the delivery trace - people lanes and typed waits - nobody else has.
Trace
A single ticket across board, code, review, and deploy - the dead wait made visible.
Tickets
Zombies, silent intake, and board-vs-git drift - the rot no standup surfaces.
Sprint health
Commitment accuracy, carryover, and scope creep - per team, quoted with receipts. “You commit 40 points, finish 24, carry the rest - every sprint.” Team grain only: never a person velocity stack-rank.
Ticket loops
Tickets that thrash instead of progressing - reopened after Done, or yo-yoing back to In Progress. Thrash, made visible.
PRs that struggled
Long open, many rounds, heavy comments, re-dos, a stalled wait - the PRs that fought their way in, receipt-backed, one click from the trace.
Reviews
Who reviews whom - the hub everything routes through, the load no roadmap named.
Deploy / DORA
The four keys - and an open admission of the one it can’t yet see.
Measured reliability
When you connect an incident source, change-failure-rate and time-to-restore stop being a proxy and become measured: each deploy correlated to the incidents it triggered. “3 of your last 5 deploys triggered a Sentry spike within 2h” - the canonical DORA definition, with the failed deploys as receipts.
Investment
New vs improvements vs KTLO vs unplanned - judged against healthy ranges, priced.
Meeting cost
Paste a calendar address and every recurring meeting is priced at your loaded cost, annualised: a daily 30-minute standup with 6 people is 767 hours and €38,330 a year. Times, durations and attendee counts only, never titles, and the verdict lands on the meeting, never the person.
Consequences & Fire Drill
The invoice for ignoring your bus factor. Pick who’s out - or let the engine pick worst-case - watch the areas orphan, and walk away with the handover checklist. Run the drill before life runs it for you.
Continuity Watch
The early-warning that watches your org’s continuity - at the only safe grain, the AREA. Each solo-owned area carries a disclosed risk tier, every input quoted, and a priced replacement range. Never a flight-risk score, never a name on a risk card. The fix arrives before the bad Tuesday does.
Fix-it ROI
Every recommendation carries a payback period - fix cost ÷ the monthly drain it addresses. “Clean the branch necropolis: ≈ 4h, payback ≈ 4 days.” The read becomes a capital-allocation memo your CFO will sign. Numbers quoted, assumptions disclosed and editable.
Measured recovery
The one recovered-money number that isn’t a relabeled sunk cost: waste-rate reduction vs your own baseline and recurring spend you verifiably stopped paying - symmetric, so a worse week subtracts. Hours first, an est € second, never a fabricated win.
Quality
The same files breaking, fixed, and breaking again - rework rate, with receipts.
Repo readiness
A readiness grade for every repository, worst-first - review-covered, tested, documented, shipping small - with the exact judged-stat gaps to level up. The Cortex/OpsLevel scorecard, computed from your git and review history, zero manual rubric. A grade on a repo, never on a person.
AI
A verdict on whether your org can absorb AI volume - six sub-factors, judged.
Estimated AI share
Trailers and bots only see AI that signs its work. Beyond that measured floor, a heuristic estimate bands your likely AI-assisted share from commit shape - always EST-labeled, “an estimate, not a measurement”, with the low bound pinned to the quoted floor so it can never contradict the fact. Org grain only, never a person.
AI tool comparison
Not just “how much AI” - which tool. Each tool’s merged-PR cohort compared to the baseline on cycle, review latency, size, and rework; the share of PRs an AI bot reviewed; and the depth-1 areas where AI churn concentrates. Below the sample floor a tool states n=X and gets no verdict - quoted, never guessed, never per person.
Measured AI cost
Real AI token and seat spend, summed from OpenTelemetry (OTLP) the tool emits natively - no vendor admin token - with per-model cost and ghost-seat detection: “declared 40 seats · 12 emitted zero telemetry.” Cost in USD, unconverted; “silent in telemetry” is a count, never a claim you’re wasting money.
Knowledge
The ownership map, colored by risk - the quiet single point of failure before it walks.
Documentation health
Which active areas have no doc at all, which docs went stale over moving code - and whether your repos are wired for AI agents. Dated, linked, judged.
Codebase Map
The import graph’s hub - the one module everything leans on, and the SPOF it hides.
People
Who’s load-bearing, who’s drowning - receipt-backed, name blurred, never a shame board.
DevEx surveys
Anonymous developer-experience surveys → a DevEx health score, per-dimension breakdown, and a trend, sitting beside the objective signals. Your own questions; responses carry no identity by construction, so a low score is a system to fix, never a person to blame.
Person & team scorecards
An honest profile of every person and team - strengths, what breaks if they vanish, and what LOSING them costs (a disclosed org-average range, never their salary). Retention direction, with the receipts under every line.
Standing
Your engineers, ordered on delivery, review, knowledge topology and momentum - and every position opens the receipts that built it, down to the pull requests. Turn a component off and the order recomputes in front of you. A thin sample is labelled fuzzy, and unmatched identities come with the link to fix them.
Work log
Every merge and review, per person and day - the standup answer with receipts instead of recollection.
Directory
Tenure, expertise, and what each person owns - the org chart that actually knows who could be paged at 2am.
Dependency map
Which team depends on which - the one-way review streets and shared-ownership areas, each a question with receipts, never a verdict on a team.
Team compare
Every team’s flow, review, quality, and sustainability - judged against the expert bar, never against each other. No rank, no team score.
Team streaks
The good weeks, stacking up - a team on a run of ≥3 healthy weeks on one stat earns a receipt-backed badge. A quiet week pauses it; only a judged off-week ends it. Earned awards, never a team-vs-team race.
Daily Pulse
Where you stand today, plus what moved since yesterday - the top problems persist, the movers refresh daily, so it’s never the same stale list.
Quarterly Report Card
Every quarter closes with a letter-graded report card - overall and eight organ sub-grades, a delta narrative vs last quarter, the money recovered, and one move for next. A graded season review, timed to renewal.
CTO Weekly Brief
One page a week: where the org stands entering the week, then the problems ranked by consequence - priced where the cost of inaction is computable, each with a why-it-ranked tag and a door - plus what improved. When a section is empty it says so; it never manufactures filler.
Exports your CFO will accept
Deterministic CSV/JSON with an audit-grade CapEx split - rule-version and run-id stamped on every figure.
CapEx policy versioning
Version your software-capitalization policy and restate prior periods on a policy change or acquisition - deterministically. See the same period under each version, the Δ, and the exact bucket rule that moved, framed to IAS 38 / ASC 350-40 (a label, not tax advice). Byte-identical on every re-run - that reproducibility is the audit value.
Who did what, on which project
Your capitalisation pack opens by person and by project, down to the individual pull requests - merge date, link, and the rule that classified each one. Every row reconciles to the bucket totals exactly, and unattributed work gets its own line instead of being spread across people who did not do it.
Targets, graded every week
Set a team target - small PRs, fast reviews - and the engine grades it automatically, every week, with receipts.
The regulars
When work really happens - late-night streaks and weekend spikes read as a system signal, never a scorecard.
Badges worth screenshotting
Earned, not awarded - achievement badges and share cards that make the good weeks travel.
Share links
One finding, one scorecard, or the whole scoreboard on an unguessable link your board opens without an account. Unlisted by default, public only if an admin opts in, with an expiry and a revoke on every link. Person names are blurred in both modes, enforced in the one resolver that can build a shared page at all - so there is no real name in the payload to reveal.
Dependency risk scan
Drop in a lockfile and see which of your dependencies are one pair of hands. 19 manifest formats, 8 registries, every package traced to the repository that produces it - and the ones we cannot trace are named with the reason rather than quietly dropped. Your file is parsed and discarded, never stored. Then ask the harder question about the code you did write.
Open-source reports
Public fragility reports on projects the internet runs on, read from nothing but the public git history. On core-js: 9.4 person-years of engineering nobody invoiced, and one person who can land a change. Maintainers are credited by name, figures the engine cannot support are refused out loud, and every page carries a right of reply. It has never had access to those repos. Ask what it says about yours.
README badge
Every report earns a shelf of badges, and only the ones the numbers support - a metric the engine refused simply has no badge. Take the slim chip for the badge gutter or the big framed card for the top of the README. The maintainer picks the one worth showing off and pastes a single line. Choosing is the consent, and the badge links back to the report that explains it.
Share bar & badge loop
Copy the link, copy the card image, or post the read in one click - and the post carries the page’s own headline, not a marketing line. Beside it sits the maintainer’s door: pick a badge, paste one line.
Rings
One command on any repository, and it cuts open like a tree: a printable cross-section of the whole life of the code, one ring per month. It reads commit metadata and never opens a source file, so it runs offline inside your own network. Same repository, same cut, every time.
From raw signal to a verdict you can act on.
Three stages. The signal you already generate, refined into a priced, receipt-backed read - with the fix on the end.
- 01
Signals + receipts
Every PR, review and ticket, measured. No guessing, no LLM in the path.
- 02
Judged vs the world
Scored against expert and peer bands.
- 03
The read, and the fix
Findings priced, risk named, every one ending in a door.
That’s why you can take it to a board: every number carries its receipt, and every problem arrives with the fix.
People intel,
without the revolt.
Who’s load-bearing, who’s overloaded - answered with receipts, wrapped in guardrails your engineers won’t revolt against.
And the one every founder feels but can’t answer: which two or three people, if they walked, would orphan half your codebase? We show you where the knowledge is concentrated - and hand you the plan to spread it. Every name comes with the pull requests that put it there.
Receipts before rhetoric
No claim about anyone lands without the PRs behind it - two readings, a stance you can check.
Praise is half the product
Good work is surfaced with the same machinery as problems. The tool credits people.
No ranked leaderboards. Ever.
No stack rank to weaponize. Consequence framing: what breaks, what orphans, what it costs.
A blur toggle on every surface
Anonymize names org-wide or per view; anything shared is always blurred.
Connect three tools. Get the verdict.
Connect, read-only
Paste a read-scoped token for your code host, then Linear and Sentry. No CSVs, no data team.
The engine reads everything
Deterministic metrics over PRs, reviews, issues, and deploys.
The verdict lands in minutes
The two things that matter, the receipts, and the fix.
One price. Everything included.
One subscription, priced per active engineer. No capacity tiers, no repo quotas, and nothing behind a paywall - not even your history.
Annual billing saves 33%. Cancel any time; you keep the period you paid for.
For the engineering lead who wants the read on their own repos before anyone signs anything.
14 days, no card, no demo call.
- The whole product on your real repositories, not a sandbox.
- Your first finding before the analysis finishes.
- Nothing to cancel, because there is nothing to enter.
For the CTO who needs the same read every week, with receipts a board will accept.
You pay for engineers who actually contributed in the window. Dormant seats cost nothing.
- Every repo, near-live. Nothing metered, nothing throttled.
- Deterministic and LLM-free: your code is never sent to a model.
- Full history, back to the first commit. Never capped by calendar.
- Not per seat, not per repo, not per feature. One price, everything in it.
- Every number links to the commit, PR or review behind it.
- An immutable period close, so last quarter cannot be rewritten.
For the org whose code cannot leave the building, and who needs one answer this quarter.
One-off engagement.
- The full €4,000 credits against your first year of Pro.
- Air-gapped on your own infrastructure. Your code never leaves your network.
- Unlimited developers, repos, projects and teams.
- Deterministic and LLM-free, benchmarked against the open-source corpus.
For the org that has to run it themselves, under their own security review.
- Everything in Pro, plus:
- Self-hosted or air-gapped, inside your own network.
- Deterministic and LLM-free, so nothing leaves your perimeter.
- A security review with real answers: the control set and a data-flow walkthrough.
Founding customers get 20% off, on top of annual, locked for life - €16 per active engineer, per month. It compounds with annual billing rather than replacing it. See what is included.
We hold no security certification today. SOC 2 and ISO 27001 are on the roadmap and not started, and we would rather you know that now than three calls in.
The questions you were about to ask.
“Isn’t this surveillance?”
No leaderboards, receipts required, praise built in - anything shared is blurred.
“Is the AI making numbers up?”
It can’t - a zero-LLM metric path, byte-identical on every rerun. Plenty of tools put a model in the scoring path, or rank people. We do neither.
“Another dashboard nobody opens?”
No - the verdict comes to you: two things that matter, priced, with the fix.
“We already have a metrics tool.”
Dashboards show. Busfactor judges - a stance, a fix, flat fee. Run both a month.
Turn the lights on.
Connect in minutes. First verdict before your next standup - every blind spot lit, priced, and fixable.