Nobody thinks about the Apps they installed three years ago and forgot

By , Salesforce CTA·1 min read·First shared on LinkedIn,

That's the problem, every AppExchange Package sitting in your Org from a project that ended, a trial that never got cleaned up, a vendor relationship that quietly ended, is not neutral. It has Permission Sets. It has API access. It has integration users with standing credentials. Some of it still has admin-level access to your data, running silently, with nobody checking whether the vendor even patches it anymore.

You wouldn't leave a former employee's login active for three years. But that's exactly what an unmanaged Package is: standing access nobody owns.

The usual excuse is "it's not doing any harm, it's just sitting there." Sitting there is the harm. Unmaintained code with live access to production data, unreviewed since installation, is precisely the kind of attack surface nobody finds until an audit or a breach forces the question.

The fix isn't complicated. Pull your installed Package list. For each one, ask: who owns this, is it still in use, does the vendor still support it. If nobody can answer, that's your answer.

App cleanup is not glamorous work. It doesn't ship features. But it's a few days now versus a security incident later

Is your Org carrying this kind of dirt?
Book a free 60-minute Salesforce Technical Debt Audit: a score for Usability and Build Quality, and your top cleanup priorities.