Overview
Reviewing your connected applications is a critical security exercise to ensure unauthorized apps don't have access to your Salesforce environment. This article walks you through Arovy's three-bucket triage framework to systematically review, approve, block, and hide detected applications — working toward an "inbox zero" state where every app is either actively monitored or revoked.
Applies to: Arovy Dashboard | Feature: Connected App Triage
Prerequisites
- Arovy account with Event Monitoring enabled
- Access to the Arovy dashboard
- Salesforce admin access (required to block applications in Salesforce directly)
Estimated Time
Varies — first-time triage can take 30–60 minutes depending on the number of detected applications. Subsequent reviews are significantly faster.
Background: The Three Triage Buckets
Before diving in, it helps to categorize every detected application into one of three buckets:
| Bucket | Description | Action |
|---|---|---|
| 1 — Approved | Recently used, recognized applications | Monitor in Arovy |
| 2 — Revoke | Unused for a long period (last detected date is old, token count > 0) | Block in Salesforce, hide in Arovy |
| 3 — Investigate | Used within the last 3–6 months, ownership unclear | Confirm with business stakeholders before acting |
Step-by-Step Instructions
Step 1: Open the Detected Applications List
Load the Arovy dashboard and scroll down to the Detected Applications section.
Applications are listed in order of Last Detected Date — the most recently active apps appear first. This date is derived from the OAuth tokens connected to each application and reflects the last time the app was actually used.
Step 2: Bucket 1 — Approve Recently Used Applications
- Identify applications near the top of the list with a recent Last Detected Date that you recognize as legitimate and in active use.
- Click the three-dot menu (⋯) next to the application.
Select Monitor App.
Fill out the application documentation fields (owner, stakeholders, criticality) and click Add New Application.
The application is now approved and will appear in your monitored applications list.
- Repeat for each recognized, recently active application.
Step 3: Bucket 2 — Revoke and Hide Inactive Applications
Scroll to the bottom of the Detected Applications list to find applications with a Last Detected Date far in the past and a token count greater than zero.
These are the highest-priority applications to remove — they have persistent access to your Salesforce but show no recent usage.
Click View Connected Apps Page to open the corresponding page in Salesforce.
Note: Arovy does not have programmatic access to block applications on your behalf. This step must be completed manually in Salesforce.
- In Salesforce, locate the corresponding application and click Block.
Return to Arovy. Scroll to the application in the Detected Applications list, click the three-dot menu (⋯), and select Hide.
The application is removed from your dashboard view. If it is ever reconnected or reactivated, Arovy will send you an alert.
- Repeat for each inactive application in this bucket.
Step 4: Bucket 3 — Investigate Ambiguous Applications
- Identify applications with a Last Detected Date within the last 3–6 months that you cannot immediately confirm as approved or safe to revoke.
- Reach out to the relevant teams or application owners to confirm whether the application is still in use.
Based on the outcome of those conversations:
- If confirmed as active and legitimate → follow Step 2 (Approve)
- If confirmed as unused or unauthorized → follow Step 3 (Revoke and Hide)
Tip: Use Arovy's stakeholder and ownership fields to document who you spoke with and what was confirmed, so there's a clear audit trail.
Expected Results
When triage is complete, your Detected Applications list should reach an "inbox zero" state:
- All legitimate, active applications are approved and monitored in Arovy
- All unused or unauthorized applications are blocked in Salesforce and hidden in Arovy (with alerts active for reconnection)
- Ambiguous applications are resolved through stakeholder conversations and actioned accordingly
- Your Salesforce environment has no unreviewed applications with persistent OAuth access
Troubleshooting
| Problem | Likely Cause | Solution |
|---|---|---|
| Detected Applications section not visible on dashboard | Event Monitoring not enabled | Contact your Arovy admin or account team to enable Event Monitoring |
| View Connected Apps Page button is missing | Application may already be revoked or the OAuth token has expired | Verify directly in Salesforce Connected Apps; if already removed, proceed to hide it in Arovy |
| Block button not available in Salesforce | Insufficient Salesforce admin permissions | Ask your Salesforce admin to block the application on your behalf |
| Hidden application reappears on the dashboard | Application was reconnected by a user | Arovy will send an alert when this happens; re-review and block if unauthorized |
| Large number of Bucket 3 applications slowing triage | First-time review of a large org | Prioritize applications with the highest token counts first; schedule stakeholder reviews in batches |
Comments
0 commentsPlease sign in to leave a comment.