Why 90 minutes is the right length
A full audit is ten to twelve business days and produces a report someone actually has to read. That is the right deliverable when a client has already decided to invest. It is the wrong deliverable when someone just wants to know whether their portal is in trouble.
Ninety minutes is enough to see every category of problem and none of the detail. That is a feature. You are not trying to catalogue 400 issues — you are trying to work out which of six areas is on fire, so the next conversation is about the right thing.
Pass 1 — Data quality (15 minutes)
Start with record counts by object and compare them to what the business thinks it has. A company that says 'about 20,000 contacts' and has 61,000 is telling you something about imports nobody owns.
- Run the duplicate management tool for contacts and companies and note the count, not the names.
- Check the fill rate on the three properties that drive routing or reporting — usually lifecycle stage, owner and country.
- Sort contacts by create date descending and look at the last 200. Imports leave fingerprints.
- Look at how many properties exist. Over 300 custom properties on a mid-market portal almost always means nobody is deprecating anything.
Pass 2 — Workflows and automation (20 minutes)
Sort workflows by last-modified date. The ones nobody has touched in eighteen months are usually still enrolling contacts. Then sort by enrolment count — a workflow that has enrolled six people in two years is dead weight; a workflow enrolling thousands with no exit criteria is a bill.
- Filter for workflows with errors and open the three most recent.
- Count workflows with no naming convention. If more than a third are untitled or named 'Copy of…', governance is the real problem.
- Check for re-enrolment turned on where it should not be, and for date-based delays that expired years ago.
Pass 3 — Integrations and API health (15 minutes)
| What to check | Where | What bad looks like |
|---|---|---|
| Connected apps | Settings → Integrations | Apps installed by ex-employees, still syncing |
| API call usage | Account → Monitoring | Sustained spikes with no known cause |
| Sync errors | Each app's sync dashboard | Thousands of failing records nobody sees |
| Webhooks | Workflow actions | Endpoints pointing at retired systems |
Pass 4 — Marketing contacts and billing exposure (10 minutes)
This pass pays for the audit more often than any other. Check how many contacts are set to marketing, what automatically sets them to marketing, and whether anyone has ever run the non-marketing cleanup. An import that flipped 30,000 unengaged records to marketing is a five-figure annual line item that nobody chose.
Pass 5 — Reporting (20 minutes)
Pick one metric leadership quotes weekly — usually pipeline created or MQLs — and find every place it appears. If two dashboards disagree, the definitions differ, and every strategy conversation downstream is negotiating with noise.
Then check date properties. Reports built on 'create date' when the business means 'became an opportunity date' are the most common silent error we find.
Pass 6 — Users, permissions and hygiene (10 minutes)
- Deactivated employees still holding record ownership.
- Super admin count. More than three on a 40-seat portal is a risk, not a convenience.
- Whether anyone can delete records in bulk, and whether there is a recovery process.
Writing it up so it gets acted on
Rank findings by annual cost or risk, not by how untidy they are. Three lines per finding: what it is, what it costs, what fixing it takes. Anything that cannot be expressed that way goes in an appendix.
Common mistakes
- Starting with workflows because they are interesting. Data quality first — bad data explains most broken automation.
- Fixing things during the audit. Change one setting and you no longer know what the baseline was.
- Producing a list of 200 findings. Nobody actions a list of 200 findings.
- Auditing without asking what leadership believes the numbers are. The gap between belief and reality is the finding.
