Slack sprawl does not announce itself. There is no outage, no failed integration, no angry email. It shows up as a slow decline: people stop finding what they need, so they stop looking, so they ask in a direct message instead, so the knowledge leaves the searchable part of the organisation. By the time anyone names the problem, two years of decisions are buried in private conversations.
We run a structured version of the audit below as a Slack Health Check. But there is nothing stopping you getting started. Work through these ten with your admin console open and you will know whether you have a problem, roughly how bad it is, and what to fix first.
Set aside two hours. Bring whoever has admin access and whoever gets asked “where do I put this?” the most.
1. Who owns Slack?
Not who administers it. Who is accountable for it.
If the answer is a name, good. If the answer is “IT, I suppose”, or three people who each assume it is one of the others, stop here – this is your first finding and every other problem on this list descends from it. Ungoverned platforms are not a technical failure. They are an ownership vacuum. You need a clear accountable owner.
2. What proportion of your channels are dead?
Pull the channel list and count how many have had no message in ninety days.
Under twenty per cent is healthy. Between twenty and forty means you have no archiving habit. Above forty means search is already degraded, because every dead channel is noise in every result. Nobody notices this happening but you do all feel the outcome.
The fix is not a purge. It is an archiving rule that runs continuously, plus a one-off clean-up to get you back to a healthy baseline.
3. Can a new starter work out where to post?
A simple test – ask someone who joined in the last month where they would post a question about a specific client, a specific project and a specific policy. Watch how long it takes and how confident they are.
If they hesitate, your channel naming is doing no work. Prefixes exist so that a person can infer the answer without asking. When there is no convention, every posting decision becomes a small social risk, and people resolve social risk by sending a direct message instead.
4. What is the ratio of public to private channels?
Count them.
A workspace that is mostly private has usually had a governance failure rather than a genuine confidentiality requirement. Private is the safe default for someone who is unsure, so a high private ratio is a signal that people do not know what belongs where, not that your work is unusually sensitive.
The related number: how much of your daily conversation happens in direct messages rather than channels. If most substantial discussion is in DMs, you are paying for a collaboration platform and using it as a messaging app.
5. Who are your guests, and should they still be here?
List every guest and every Slack Connect connection. For each one, answer two questions: who invited them, and are they still working with you?
This is the finding that most often makes a leadership team sit up, because the answer is frequently that a former contractor or a supplier from a finished project still has a live seat in channels nobody thinks about.
Then check the harder version: for each guest tier, what can that person actually open, search, download and export? Not what you intended – what the permissions permit. Those two things drift apart quietly.
6. What apps are installed, and who approved them?
Pull the installed app list. For each app, establish who approved it, what data it reaches, and whether anyone still uses it.
Most workspaces have apps that were installed for a trial that ended, a project that finished or a person who has left. Each one holds a data connection nobody is reviewing. If app approval is currently open to any member, that is a finding in itself.
7. Where does AI sit in all of this?
Newly relevant, and most audits miss it entirely.
Which AI features are switched on, for whom? Slackbot runs on the higher plan tiers and reaches what each user can already see, which means your AI exposure is exactly your permissions exposure. If question five turned up guests with more access than expected, that finding now has a second dimension.
Then: has anyone connected Slack’s AI outward to your own systems? And is anyone reviewing that list? New capability ships automatically, and admin settings do not apply to features that have not been released yet, which means the control here is a review cadence rather than a configuration.
8. Does your retention position match your obligations?
Check what your message and file retention is actually set to, then check what your privacy policy, funding agreements or record-keeping obligations require.
For organisations in community services, aged care and government work, this is the item most likely to produce an uncomfortable answer. Slack’s defaults are set for convenience, not for your compliance position, and nobody ever revisits them after go-live.
9. What is your integration doing?
If Slack and Salesforce are connected, ask what the connection is actually for.
The common pattern is notifications flowing one way, at volume, with no return path. Notifications that nobody acts on train people to ignore Slack, which is worse than no integration at all. A good integration puts a decision in front of the person who can make it, and lets them make it there.
10. When did anyone last look?
If the answer is “at go-live, three years ago”, the honest finding is that you do not have a governance problem so much as a maintenance problem. Platforms drift. The organisations whose workspaces stay usable are not the ones that set it up perfectly. They are the ones that look at it quarterly.
Reading your results
Roughly, three patterns emerge.
Mostly healthy, a few gaps. Usually guests, apps and retention. Fixable in weeks by your own team with the rules written down. You do not need a consultant. You need an owner and an afternoon.
Structurally tired. Dead channels, no naming convention, conversation drifting into direct messages, an integration nobody trusts. The structure needs repairing without disrupting the people using it every day, which is a different and more delicate job than building it fresh. That is what a Slack Refresh is.
Never properly founded. No ownership, no conventions, no access model, and the workspace has grown regardless. The honest answer is to do the foundational work now, properly, once. It costs less than the third attempt at patching it.
The part worth saying plainly
None of this is exotic. There is no proprietary framework here and nothing you could not do yourself with the admin console and a free afternoon. Hopefully the questions are useful.
If you get to the end of the ten and you are not sure what your results mean, that is a reasonable thing to want a second opinion on. A Slack Health Check is two to three weeks, evidence-based, and produces a findings report and a prioritised plan you own whether or not you do anything else with us.
If your resources are stretched and you would like a hand kicking off let us know. Â
Either way, do the audit. The cost of not knowing compounds quietly.
Not sure where you stand on any of this? Get in touch with Andrew for a Slack Health Check, and we’ll give you a straight answer about what to fix first.

Andrew France
Chief Exceutive Officer
Andrew has spent close to a decade in and around the Salesforce ecosystem, including founding Destined (acquired by Media Monks) and building one of the region's leading Salesforce consulting partners. His background covers the not-for-profit sector, healthcare, financial services and professional services, with hands-on experience in large enterprise transformation and AI-led business change.