First response
- Image or back up the machine, application and databases.
- Interview operators and capture critical workflows and exceptions.
- Inventory files, dependencies, configuration and startup.
- Observe inputs, outputs and database/file changes.
- Identify network, printer, serial and hardware integrations.
- Rank functions by business impact and recovery urgency.
Create the first useful documentation
Produce a one-page architecture, dependency list, configuration locations, backup/recovery steps and known failure points. Document what is observed versus assumed before making code or platform changes.
Use the archaeology checklist, configuration recovery, system documentation and the pillar.