Scope
Your whole system, not one component of it.
Most reviews are commissioned about the thing that's currently
hurting, and stop there. The useful version looks at the system that
produced the symptom, because a capacity problem is often an
architecture decision, a cost problem is usually a capacity decision,
and a security finding is often an instrumentation gap that let it go
unnoticed.
So this covers the application and the infrastructure it runs on,
whoever built it and wherever it runs. We're not reviewing it to sell
you a migration.