Formstack Audit & Optimization

You Cannot Fix an Estate You Have Never Fully Seen

A Formstack audit is a fixed-scope review of what you actually have: every form, template, integration, customization and licence, plus what is failing and what nobody owns. Twopir Consulting delivers it as an inventory, a findings list ranked by business risk, and a remediation roadmap you can act on with us, with someone else, or on your own.

Audit Model
WHAT WE EXAMINE Forms & Templates Active · Dormant · Duplicated Integrations & Custom Code Working · Broken · Unknown Licences & Usage Security Config Failure Data TWOPIR ASSESSMENT LAYER Inventory Everything, with owner and volume Findings by Risk Evidence attached Severity stated Roadmap Sequenced by risk Effort estimated FIXED SCOPE · YOURS TO ACT ON WITH ANYONE 2πr DECISIONS YOU CAN MAKE Fix Now What is actively losing data or money Retire What exists but is no longer used True Cost What the estate costs to run as it stands INVENTORY · TEST · RANK · SEQUENCE · REPORT
Definition

What Is a Formstack Audit?

A Formstack audit is a structured assessment of an existing Formstack estate that produces three things: a complete inventory, a list of findings ranked by business risk with evidence attached, and a remediation roadmap sequenced by that risk. It is diagnostic work, deliberately separated from delivery work, so the findings are not shaped by what would be convenient to sell afterwards.

It is the right first step whenever you have inherited an estate, cannot account for what exists, suspect something is failing silently, are being asked to justify the licence spend, or are about to start a significant build on foundations nobody has examined.

The output is yours. The inventory, findings and roadmap are deliverables you own and can act on with us, with another partner, or with your own team. We say this explicitly because an assessment whose conclusion is always "engage us for a large programme" is a sales exercise wearing an audit's clothes, and the whole value of a diagnostic is that its findings are trustworthy.

Scope

Eight Domains, Each With a Specific Question

Each domain answers one question that leadership can act on. If a domain does not apply to your estate, we say so rather than padding the report with it.

01 · Form Estate

What exists, and which of it matters? Most estates have a small core carrying the volume and a long dormant tail nobody has looked at.

  • Complete inventory with submission volume
  • Dormant and duplicate identification
  • Ownership — and forms with no owner
  • Naming and folder consistency
  • Consolidation opportunities

02 · Integration Health

Is data actually arriving where it should? The domain that most often produces the first genuinely alarming finding.

  • Every connection mapped, including undocumented ones
  • Reconciliation of submissions against records created
  • Failure and error rate analysis
  • Duplicate creation assessment
  • Connections that have silently stopped

03 · Security & Compliance

Is the configuration consistent with your obligations? Capability and configuration are different things, and the gap is where risk lives.

  • Access and permission review
  • Handling of sensitive data in transit and at rest
  • Retention configuration against stated policy
  • Consent capture and audit evidence
  • Webhook and API credential hygiene

04 · Template Estate

Can your document templates be safely changed? Usually the domain where consolidation produces the largest saving.

  • Template inventory with usage frequency
  • Near-duplicate and variant analysis
  • Merge field integrity checks
  • Version control and approval practice
  • Generation failure review

05 · Customization Register

What is custom, why, and can it still be upgraded around? Inherited custom code is frequently reimplementing a native feature.

  • Inventory of custom CSS, scripts and platform code
  • Justification and current owner per item
  • Upgrade-safety assessment
  • Items now superseded by native capability
  • Items with no test coverage

06 · Data Quality

Is the data the estate produces actually usable? The domain that explains why reporting is not trusted.

  • Free-text fields that should be structured
  • Inconsistent option sets across forms
  • Duplicate records traced to capture design
  • Required data arriving empty
  • Field naming alignment with the CRM

07 · Process & Performance

Where does work wait, and where do people give up? Formstack's own analytics answer much of this once someone reads them.

  • Abandonment and field bottleneck analysis
  • Approval cycle time and queue ageing
  • Steps with no timeout or escalation
  • Rework and rejection rates
  • Manual steps that remain in an automated process

08 · Licence & Consumption

What are you paying for, and what are you using? Including the consumption limits that will become a problem before anyone notices.

  • Entitlements against actual usage
  • User accounts that are no longer active
  • API quota consumption and headroom
  • Salesforce API impact where native packages are used
  • Capabilities you pay for and do not use
Signals

Six Signals That an Audit Is Overdue

None of these is a crisis on its own. Two or more together usually means the estate has drifted past the point where anyone can reason about it confidently.

Nobody Can Produce a Complete Inventory

If nobody can list every form, template and integration and say who owns each, then nobody can assess the impact of a change. Every decision after that point is made partly blind.

Reporting Is Quietly Distrusted

People export the data and rework it in a spreadsheet before presenting it. That behaviour is a precise diagnostic: it means someone has already found the numbers wrong and worked around it rather than raising it.

Failures Are Found by Customers

The first signal that something stopped working is somebody asking why they never heard back. That means there is no monitoring, and the estate has been running on luck rather than design.

The Person Who Built It Has Left

Institutional knowledge walked out with no documentation behind it. The estate still works, but nobody can safely change it — which means it will gradually stop matching how the business actually operates.

Finance Is Asking What It Is For

Renewal is approaching and nobody can justify the tier, the seat count or the add-ons. An audit turns that conversation from an opinion into a usage report with a recommendation attached.

A Big Build Is About to Start

Adding a significant new process to foundations nobody has examined is how a project inherits someone else's problems on day one — and then owns them, because it was the last thing to touch the estate.

What You Receive

Four Deliverables, and Who Each One Is For

Audit deliverables
DeliverableWhat it containsWho uses it
Estate inventoryEvery form, template, integration, customization and user account, with volume, owner and current status.The platform owner. It becomes the working register the estate is managed from afterwards.
Findings registerEach finding with its evidence, its business impact, its severity and what causes it. No finding without evidence.The platform owner and their technical team, plus compliance where security findings apply.
Remediation roadmapFindings sequenced by risk and dependency, each with an effort indication and a clear statement of what improves.Whoever decides what gets funded and in what order.
Executive summaryWhat is at risk, what it is costing, what we recommend doing first, and what can safely wait.The sponsor or leadership team. One read, no platform vocabulary required.

Severity is about business impact, not technical elegance. A form with untidy naming and a form that has been silently dropping submissions for two months are not the same finding, and a report that lists them next to each other has failed at the one thing a findings register exists to do. Our severity scale is anchored on data loss, compliance exposure, revenue impact and operational cost — in that order.

How It Runs

Five Steps, Fixed Scope

The demand on your team is deliberately small: read access, one kickoff session and a handful of short interviews. An audit that consumes a month of your people's time has defeated its own purpose.

Step 01

Access & Kickoff

Read access to the Formstack account and the connected systems, plus a session to agree what matters most to you. Where access cannot be granted, we work from exports instead — that constraint is normal and we plan around it.

Step 02

Inventory

Systematic capture of everything that exists, with volume, owner and status. This step routinely surfaces assets nobody knew about, and occasionally an integration that stopped working months earlier.

Step 03

Test & Reconcile

Evidence gathering rather than inspection: reconciling submissions against records created, checking merge integrity, reviewing error and failure data, and testing the paths that matter. Findings without evidence do not enter the register.

Step 04

Interview

Short conversations with the people who run the processes. They know which form everyone works around and which report nobody trusts — information that does not appear in any export.

Step 05

Report & Walkthrough

The four deliverables, presented in a working session rather than emailed. You leave that session able to decide what to fix first, and the documents are yours to act on with anyone.

Common Questions

Answers Before the First Call

Read access to the Formstack account and read access to the systems it connects to, which for most clients means the CRM. We do not need write access at any point during an audit, and we would decline it if offered — a diagnostic engagement should not be able to change the thing it is assessing. Where your security policy does not permit third-party access at all, we can work from exports and a screen-sharing walkthrough; it takes longer and the inventory is slightly less complete, but the findings are still sound.

An audit is a matter of weeks rather than months, scaled to the size of the estate and confirmed before we start. The demand on your side is deliberately small: a kickoff session, a handful of short interviews with people who run the processes, and whatever is needed to arrange access. We keep it that way on purpose — an assessment that consumes a month of your team's attention has already cost more than several of the findings it will produce.

Sometimes, and quite often not. Plenty of audits conclude that the estate is broadly sound with a handful of specific fixes, several of which your own team can do. The roadmap states which findings need external help and which do not, and there is no obligation to engage us for any of it — the deliverables are yours. We are explicit about this because an assessment that always recommends a large programme is not a diagnostic, and its findings should not be trusted by anyone including the people who commissioned it.

It gives you the evidence to have that conversation properly, which is not the same as promising a saving. The licence and consumption domain compares entitlements against actual usage: inactive accounts, capabilities you pay for and do not use, and consumption headroom. Sometimes the finding is that you are over-provisioned. Sometimes it is that you are approaching a limit that will become an incident, and the recommendation is to spend more before that happens. Either way you go into a renewal with usage data rather than an opinion.

An absence of reconciliation. Very few estates have a standing check comparing submissions received against records created in the destination system, which means a partial failure is invisible until somebody happens to notice a gap. It is also among the cheapest things to fix — usually a scheduled report and an owner — and it changes the risk profile of the whole estate, because it converts the entire class of silent failures into visible ones.

Next Step

Start With What You Have. Not With What You Would Build.

An audit is the lowest-commitment way to work with us and the fastest way to find out whether your estate has a problem worth spending money on. If it does not, the report will say so.

Read access only. Fixed scope. The inventory, findings and roadmap are yours to act on with anyone.