Tech Stack Documentation Template
Four documents and four sheets that record every integration as a directed edge, then rank your applications by what breaks downstream rather than by cost.
Free download · No account needed
Blast Radius
Penrose, 20 applications, 36 integrations
Downstream reach is the transitive count: everything that goes stale when this one stops. Derived from the Integration Map, never edited by hand.
| # | By downstream reach | Reach | $/yr | Spend # |
|---|---|---|---|---|
| 1 | Stanchion HRIS | 18 | 69,360 | 4 |
| 2 | Junction Automate no owner | 15 | 0 | 16 |
| 3 | Ivory Identity | 14 | 24,480 | 10 |
| 4 | Kelvin Service Desk | 12 | 32,400 | 8 |
| 5 | Hookline Relay no owner | 11 | 0 | 17 |
| … | ||||
| 11 | Helix CRM | 9 | 136,800 | 1 |
| 18 | Corvid Docs Suite | 0 | 97,920 | 2 |
All 20 positions differ between the two rankings
The most expensive application in the estate is eleventh on reach. The second most expensive has nothing downstream of it at all. Second place on reach is a free tier, so it appears on no invoice and in no identity list, and a two-source inventory has no row for it.
Removal test, a different question: deleting Marlow Warehouse costs 99 of the graph's 166 reachable pairs, and third place is a scheduled spreadsheet at 70.
A stack document that groups applications under CRM, marketing, analytics and finance is fine on a slide and useless at two in the morning. The only question then is what feeds the broken thing and what the broken thing feeds, and both answers live in the edges rather than in the list. Nobody writes the edges down, partly because discovery normally stops at the two sources that produce a tidy inventory: the identity provider's application list and last year's invoices.
So this pack discovers from three sources, and the third one changes the picture. On the worked estate here, a 20 application company called Penrose, identity finds 10 applications and billing finds 15, and the union of those two is still 15. The integration configuration inside them finds 20. Five applications, a quarter of everything running, sit in no identity list and on no invoice. They are an automation platform on a free tier, a webhook relay, a scheduled spreadsheet, an SFTP drop to a logistics partner and a survey tool.
Then two pieces of arithmetic on the graph. Rank by downstream reach and all twenty positions differ from the spend order: the CRM leads on cost at $136,800 a year and lands eleventh, while second place on reach costs nothing. Record a credential style on every edge and 14 of 36 authenticate as a person, ten of those as somebody who has left. Hand River the exports, or take the Word and CSV files blank. What to renew is a renewal calendar question, and replacing one of these systems is a migration plan.
What's in the pack
Application Register
One column per discovery source, so the applications that appear only inside somebody else's integration configuration stay visible as a gap.
Integration Map
Every edge with a source, a target, a direction, what moves, the credential it authenticates as, its cadence and its silent-failure risk.
Blast Radius
Downstream reach and upstream depth per application, computed transitively, plus the reachable pairs the graph loses if each node is removed.
Owner and Renewal Cross-reference
The join that gives every application a human being and a date, including the rows that currently have neither.
Stack Overview
What discovery found from each source, both rankings side by side, and the credential findings written as findings rather than as notes.
Integration Topology
The graph drawn in text, with the tiers, the bridge nodes and how to read it backwards during an incident and forwards during a migration.
Integration Policy
Seven rules, each tied to a specific thing discovery found, including why a personal credential breaks at offboarding.
Owner Responsibilities
What owning an application or a single edge commits you to, and the extra two duties that come with owning the glue.
How to use it
- 1
Open in River, or take it blank
Open the pack in River and hand it the identity export, the invoices and whatever integration configuration you can screenshot, or download the Word documents and CSV sheets and fill them in yourself.
- 2
Discover from three sources, not two
Identity, billing, and then the connections page inside each system at the middle of the business. Record which sources found each application in separate columns.
- 3
Turn every integration into a directed edge
Source, target, payload, credential, cadence, owner. One row per direction, because the two halves of a sync fail independently.
- 4
Compute reach, then join the credentials
Rank by transitive downstream reach and compare it against the spend order. Then join the credential column against your leaver list, which is where the findings are.
Frequently asked questions
Is this template free?
Yes, and nothing is gated. The zip holds four Word documents and four CSV sheets, no account and no card. Edit with AI is the optional half: River crosses the three discovery sources, builds the edge list and computes the reach ranking for you. More packs sit in the template library.
What format are the downloaded files?
Four Word documents and four CSV sheets, zipped. Excel, Numbers and Google Sheets open the sheets directly, and the overview, topology, policy and responsibilities documents open in Word or Pages. The topology diagram is drawn in text inside the document, so nothing needs a diagramming tool to read or to edit.
Why not just group the applications by category?
Because a category tells you what something is, and every question worth asking is about what it connects to. Category is a filter on the register here, not the organising idea. The artifact that answers an incident is the edge list, and the artifact that sizes a migration is the reach count derived from it.
Our identity provider already lists every app. Why a third source?
It lists every application that federates. Free tiers, webhook relays, scripts and partner file drops do not, and they are not billed either, so two-source discovery has no row for them. On the worked estate that is five of twenty applications, and one of them is second in the whole portfolio by downstream reach.
Where do undeclared applications actually come from?
Often from a user approving one directly. Identity platforms let users consent on their own behalf for permissions that do not need an administrator, and Microsoft notes you cannot revoke those grants in the portal, only through the API. So they arrive with no purchase and no approval record.
Is downstream reach not just the same as spend, roughly?
It is not, and that is the point of computing it. On the worked estate all twenty positions differ between the two rankings. The most expensive application is eleventh on reach, the second most expensive has nothing downstream of it at all, and second place on reach is a free tier the invoices cannot see.
Does this decide what to cut or whether a vendor is safe?
No, deliberately. This map records what connects to what and who answers for it. Whether the spend is justified belongs in a renewal calendar, whether a vendor may hold your data is a vendor risk review, and getting people onto a replacement is a rollout pack.
Map the edges, not the categories
Take the Word documents and CSV sheets blank, or open this pack in River and let it discover from all three sources first.
Edit with AI