How to Triage Connected Apps

Have more questions? Submit a request

Overview

Reviewing your connected applications is a critical security exercise to ensure unauthorized apps don't have access to your Salesforce environment. This article walks you through Arovy's three-bucket triage framework to systematically review, approve, block, and hide detected applications — working toward an "inbox zero" state where every app is either actively monitored or revoked.

Applies to: Arovy Dashboard | Feature: Connected App Triage 


Prerequisites

  • Arovy account with Event Monitoring enabled
  • Access to the Arovy dashboard
  • Salesforce admin access (required to block applications in Salesforce directly)

Estimated Time

Varies — first-time triage can take 30–60 minutes depending on the number of detected applications. Subsequent reviews are significantly faster.


Background: The Three Triage Buckets

Before diving in, it helps to categorize every detected application into one of three buckets:

BucketDescriptionAction
1 — ApprovedRecently used, recognized applicationsMonitor in Arovy
2 — RevokeUnused for a long period (last detected date is old, token count > 0)Block in Salesforce, hide in Arovy
3 — InvestigateUsed within the last 3–6 months, ownership unclearConfirm with business stakeholders before acting

Step-by-Step Instructions

Step 1: Open the Detected Applications List

  1. Load the Arovy dashboard and scroll down to the Detected Applications section.

    Applications are listed in order of Last Detected Date — the most recently active apps appear first. This date is derived from the OAuth tokens connected to each application and reflects the last time the app was actually used.


Step 2: Bucket 1 — Approve Recently Used Applications

  1. Identify applications near the top of the list with a recent Last Detected Date that you recognize as legitimate and in active use.
  2. Click the three-dot menu (⋯) next to the application.
  3. Select Monitor App.

  4. Fill out the application documentation fields (owner, stakeholders, criticality) and click Add New Application.

    The application is now approved and will appear in your monitored applications list.

  5. Repeat for each recognized, recently active application.

Step 3: Bucket 2 — Revoke and Hide Inactive Applications

  1. Scroll to the bottom of the Detected Applications list to find applications with a Last Detected Date far in the past and a token count greater than zero.

    These are the highest-priority applications to remove — they have persistent access to your Salesforce but show no recent usage.

  2. Click View Connected Apps Page to open the corresponding page in Salesforce.

    Note: Arovy does not have programmatic access to block applications on your behalf. This step must be completed manually in Salesforce.

  3. In Salesforce, locate the corresponding application and click Block.
  4. Return to Arovy. Scroll to the application in the Detected Applications list, click the three-dot menu (⋯), and select Hide.

    The application is removed from your dashboard view. If it is ever reconnected or reactivated, Arovy will send you an alert.

  5. Repeat for each inactive application in this bucket.

Step 4: Bucket 3 — Investigate Ambiguous Applications

  1. Identify applications with a Last Detected Date within the last 3–6 months that you cannot immediately confirm as approved or safe to revoke.
  2. Reach out to the relevant teams or application owners to confirm whether the application is still in use.
  3. Based on the outcome of those conversations:

    • If confirmed as active and legitimate → follow Step 2 (Approve)
    • If confirmed as unused or unauthorized → follow Step 3 (Revoke and Hide)

    Tip: Use Arovy's stakeholder and ownership fields to document who you spoke with and what was confirmed, so there's a clear audit trail.


Expected Results

When triage is complete, your Detected Applications list should reach an "inbox zero" state:

  • All legitimate, active applications are approved and monitored in Arovy
  • All unused or unauthorized applications are blocked in Salesforce and hidden in Arovy (with alerts active for reconnection)
  • Ambiguous applications are resolved through stakeholder conversations and actioned accordingly
  • Your Salesforce environment has no unreviewed applications with persistent OAuth access

Troubleshooting

ProblemLikely CauseSolution
Detected Applications section not visible on dashboardEvent Monitoring not enabledContact your Arovy admin or account team to enable Event Monitoring
View Connected Apps Page button is missingApplication may already be revoked or the OAuth token has expiredVerify directly in Salesforce Connected Apps; if already removed, proceed to hide it in Arovy
Block button not available in SalesforceInsufficient Salesforce admin permissionsAsk your Salesforce admin to block the application on your behalf
Hidden application reappears on the dashboardApplication was reconnected by a userArovy will send an alert when this happens; re-review and block if unauthorized
Large number of Bucket 3 applications slowing triageFirst-time review of a large orgPrioritize applications with the highest token counts first; schedule stakeholder reviews in batches

 

Articles in this section

Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.