Bring the current product.
The working version, a reproducible problem and the intended user task are a useful start. Access to code and environments follows agreed permissions; never send credentials through the enquiry quiz.
Follow the real task.
Try access, the main action, saving a result and recovery. A polished screen can still hide a broken permission or missing handover. Record what actually happens.
Separate findings from fixes.
A useful review names the issue, the conditions that reproduce it and its impact on the task. Agree which fixes to implement and how to check them; a report alone does not repair the product.
Make the next release ownable.
Clarify account access, deployment, monitoring, data export and support. Preserve the parts that work and name the remaining risks before you expand.
