Resources

Salesforce Org Health for Software Companies

What 3-to-10-year-old orgs break first — and the 10-minute check for each one.

Software companies running Salesforce for 3 to 10 years hit the same 6 failures, in roughly this order: permission sets become a clone of a clone with no baseline, integration users outlive the GTM tools they were built for, lead and opportunity routing accumulates a new rule with every reorg instead of replacing the old one, custom fields and objects survive the pricing model or motion that created them, automation was sized for an org with far fewer connected tools than it has today, and Connected Apps keep standing OAuth grants for SaaS tools the company stopped using. Each one has a 10-minute check you can run yourself. A Wrenk health check runs all of them, plus 200 more, in about 60 seconds.

Why this list exists right now

Right now, software and SaaS companies are posting more roles referencing Salesforce administration, RevOps, or sales-ops platform ownership than any other industry we track — ahead of financial services, IT services, and general technology companies. Different companies, same job description underneath: a permissions model nobody trusts anymore, an integration list longer than anyone can account for, and a lead routing setup that's been patched through two or three reorgs.

That pattern tracks with how software companies actually grow. Headcount scales in bursts, the GTM stack changes every time a new tool wins internal buy-in, and territories get redrawn every time the sales org reorganizes around a new segment or motion. Salesforce absorbs all of that change and rarely gets cleaned up afterward. Below is what breaks first, in the order it usually shows up.

The 6 things that break first

1

Permission sets are a clone of a clone

Symptom: Fast headcount growth means onboarding a new AE, SDR, or CS rep usually meant cloning whatever permission set the person next to them had, rather than assigning a role-based baseline. Years and a few reorgs later, dozens of overlapping sets exist with no clear owner and no record of why any one of them diverged from the others.

What it costs: Some reps end up with more data access than their role needs — comp data, forecast visibility into territories they don't own, records from a business unit that was sold off. Admins can't safely revoke access without knowing what quietly depends on it, so the sprawl just keeps growing.

10-minute check: Pull the permission sets assigned to users hired in the last 12 months and diff them against the sets assigned to people in the same role who've been there 3+ years. If they don't match, there's no baseline left to enforce.

2

Integration users outlive the tools they were built for

Symptom: Growth-stage software companies swap GTM tools often — comp planning, CPQ, marketing automation, conversation intelligence, RevOps analytics — and each one gets its own dedicated integration or API user at connection time. When a tool gets replaced, the integration user that authenticated it is rarely deactivated along with it.

What it costs: A stale integration user keeps standing API access, and sometimes broad object permissions, to a system nobody is monitoring anymore. It also counts against active-user totals the next time someone reconciles licensing.

10-minute check: List every API-only or integration user and its last-login date, then cross-reference against the GTM stack you're actually paying for today. Anything that hasn't authenticated in 90-plus days almost certainly belongs to a retired tool.

3

Lead and opportunity routing gained a rule with every reorg

Symptom: As the sales org restructures around new segments, territories, or an expansion motion, assignment rules and routing flows get added on top of the old ones instead of replacing them — because nobody wants to be the one who breaks live lead routing testing the removal.

What it costs: Leads land with the wrong rep, especially at territory or segment boundaries, or sit unassigned entirely. Reps end up chasing down misrouted leads by hand instead of the system catching it, and pipeline reporting reflects wherever the lead actually landed rather than where it should have.

10-minute check: Count the active Lead and Opportunity assignment rules and their entry criteria, then check whether any two rules can fire on the same record. Overlapping criteria is the tell that an old rule was never retired when the new one shipped.

4

Custom fields and objects survive the motion that created them

Symptom: Fields and objects built for a pricing model the company has since changed, an ABM push that wrapped up, or a partner motion that got deprioritized stay on page layouts and reports long after the initiative ended.

What it costs: Reps scroll past dead fields on every record, new hires learn 'how we do things' from a layout that's years out of date, and reports mix data from the current motion with leftovers from the old one — making the numbers harder to trust than they should be.

10-minute check: Identify custom fields with no updated values across records in the trailing 6-12 months that are still sitting on an active page layout. Anything that comes back is either genuinely dormant or should have been retired already.

5

Automation was sized for an org with fewer connected tools

Symptom: Flows, triggers, and webhooks get added one integration at a time — a CDP or data-warehouse sync here, a comp platform there, a marketing automation tool on top — without anyone tracking the cumulative daily API call volume all of them draw from the same pool.

What it costs: The org creeps toward its daily API limit, save performance degrades during peak hours, and integration sync jobs start failing intermittently in ways that get blamed on the vendor rather than the shared limit everything is competing for.

10-minute check: Open Setup > API usage and look at the trend over the trailing 30 days, then count how many integrations and Connected Apps hold API access. If the count keeps growing and nobody's reviewed which ones actually need real-time access, that's the gap.

6

Connected Apps keep OAuth grants for tools the company stopped using

Symptom: Every SaaS tool connected to Salesforce — comp platforms, RevOps tools, data enrichment, forecasting — requested OAuth scopes at connection time. When the company swaps one out, which happens often while a software company is still iterating on its own stack, the old Connected App registration is rarely revoked along with the subscription.

What it costs: An unused Connected App with an active OAuth grant is exactly the kind of thing a SOC 2 review or security questionnaire flags, and each one left standing is a credential surface nobody is actively watching.

10-minute check: Review Setup > Connected Apps OAuth Usage sorted by last-used date. Anything untouched for 6-plus months while still holding an active grant is worth revoking.

What a health check finds in 60 seconds

Running the 6 checks above by hand takes an afternoon per org. A Wrenk health check runs the same categories, plus 200 more, in about 60 seconds — no SOQL required.

Unused fields

Custom fields with no data across records that are still sitting on active page layouts — the leftovers from a pricing model or GTM motion the company already moved past.

Automation density per object

How many flows, triggers, and process builders fire on a single object, and how much cumulative API volume they draw against the org's daily limit — the pattern behind integration jobs that fail for no obvious reason.

Permission sprawl

How many permission sets exist, how many are clones of a clone, and whether there's still a role-based baseline anyone could point to — the sprawl from the first finding above.

Integration users

Every API-only or integration user in the org, when it last authenticated, and what it's connected to — so a stale credential from a tool the company stopped paying for doesn't sit unnoticed.

Deprecated auth flows

Connected Apps still holding OAuth grants with no recent activity, or a connection still authenticating with the SOAP login() call Salesforce is retiring — common at companies that iterate on their GTM stack often.

Related reading

See what's actually breaking in your org

Answer a few questions about your setup and run a free health check — no account, no SOQL, no per-org fee. Treat it as the first step before pointing an agent at your org, not a replacement for one.

Run Free Health Check