diff --git a/howto/puppet.md b/howto/puppet.md
index 99b545628aaf47a0065024602cdc1c54b95b1081..d0a5f6dcdd84577d835ffe646a3902b3a081f892 100644
--- a/howto/puppet.md
+++ b/howto/puppet.md
@@ -791,15 +791,19 @@ doesn't have to be highly available right now. This could change in
 the future if we rely more on it for deployments.
 
 ## Design
+
+TODO. review
+<https://bluesock.org/~willkg/blog/dev/auditing_projects.html> and
+expand this design accordingly.
+
+TODO: add a lead here.
+
 <!-- how this is built -->
 <!-- should reuse and expand on the "proposed solution", it's a -->
 <!-- "as-built" documented, whereas the "Proposed solution" is an -->
 <!-- "architectural" document, which the final result might differ -->
 <!-- from, sometimes significantly -->
 
-<!-- a good guide to "audit" an existing project's design: -->
-<!-- https://bluesock.org/~willkg/blog/dev/auditing_projects.html -->
-
 ### Glossary
 
 This is a subset of the [Puppet glossary](https://puppet.com/docs/puppet/latest/glossary.html) to quickly get you