Make monday.com work with Microsoft 365 & SharePoint →
Workspace Doctor logo

Workspace Doctor

Tiberiu Jinga

16 installs, since June 15, 2026.   8 installs/month.   App updated July 8, 2026. Listing updated July 21, 2026.

Hosted by monday.com Not paid No touch

Scan, score & fix your monday workspace in one click

Workspace Doctor is a one-click health check for your monday.com account. Built for admins, ops leads, and workspace owners on large or fast-growing accounts, it scans every board for the issues that quietly slow teams down — stale work, status-label drift across boards, items assigned to people who left, and workspaces no one uses.


You get a single 0–100% health score across four categories, plus a prioritized list of findings you can act on directly: archive a stale board in one click, jump straight to affected items, and tune thresholds to your team's cadence.


🩺 What it scans:


📋 Board Health - boards no one has updated past your staleness threshold, and boards left empty past the grace period.


🏷️ Status Consistency (the headline feature) - three-layer detection of label drift: fuzzy matching for typos ("Done"/"done!"), a dictionary for synonyms ("Completed"/"Resolved"), and AI embeddings for domain terms ("Wrapped Up"). Same-column exclusion prevents false positives.


👤 User Hygiene - items still assigned to deactivated users, so handoffs don't fall through the cracks.


📊 Adoption - workspaces with very low recent activity: abandoned imports, half-started initiatives, ghost departments.


📈 Track, schedule & share - a history chart shows your score trend over 30/90/365 days. Weekly checks run on the day you choose, an email summary lands when a check finishes, and findings export to CSV for stakeholders.


💡 When to use it - before a quarterly cleanup, after a reorg or offboarding wave, or on a weekly schedule to stay tidy as you scale.


🔒 Privacy & data handling - runs entirely on monday's own infrastructure (monday code), never on third-party servers; data is encrypted at rest (AES-256). Only anonymous status labels reach the AI layer - never board content, item names, or user details. Four minimal OAuth scopes, and everything is deleted on uninstall.


💬 Questions or feedback? leano-app.com/workspace-doctor or leano-app.com/contact.

Security & Compliance

Security

Does the developer periodically perform penetration testing?

Not answered

Does the developer have a dedicated security and privacy point of contact for such issues or questions?

Yes
support@leano-app.com

Does the app restrict redirects and forwards only to approved destinations, or show a warning when redirecting to potentially untrusted content?

Yes
The only redirect is the fixed OAuth REDIRECT_URI; "View in monday" links are https:// with validated slug/board-id; never user-supplied URLs.

Does the app protect against mass parameter assignment attacks?

Yes
zod strips unknown keys (no .passthrough()); DB writes use an explicit key allow-list.

Does the app perform encoding and sanitization on all user supplied parameters to protect against Cross-Site Scripting?

Yes
zod validates every endpoint server-side; React auto-escapes all rendered data; no dangerouslySetInnerHTML/eval.

Does the developer protect all state-changing actions against Cross-Site Request Forgery (CSRF)?

Yes
Auth is a monday session JWT in the Authorization header (not cookies) → no CSRF surface; OAuth uses an HMAC-signed state.

Does the developer have mechanisms to notify monday.com in case of a security breach?

Yes
Notify monday via partner support within 24h, notify affected customers via support@leano-app.com, document remediation.

Does this developer have a process for installing application-level updates and security patches for the service (such as software packages and databases)?

Yes
Platform patches by monday code; deps via npm/npm audit; fixes deployed via mapps code:push.

Compliance

Is the app certified with the information security standard ISO/IEC 27001:2022?

Not answered

Is the app compliant with the Health Insurance Portability and Accountability Act (HIPAA)?

Not answered

Is the app certified with System and Organization Controls (SOC 2 or SOC 3)?

Not answered

Is the app compliant with the General Data Protection Regulation (GDPR)?

Yes
Lawful basis (OAuth consent), data minimization, deletion-on-uninstall, access via iframe, privacy policy.

Data

Does the app send any data outside of monday.com? If yes, indicate whether the data is customer-submitted (e.g., board names, item names, doc content) or non-customer-submitted (e.g., account ID, board ID, user ID).

Yes
Yes - short status-label strings (e.g. "Done", "In Progress") to OpenAI's text-embedding-3-small for clustering. No IDs, names, emails, PII, or item/board content. (Customer-submitted: status labels only.)

Where does the app store logs data?

monday
monday code's centralized log stream via the SDK Logger; no external log store.

Where does the app store the app data?

monday
monday code Document DB for scan results/settings; OAuth tokens in SecureStorage, encrypted at rest.

Does the developer ensure application logs do not contain secrets or personally-identifiable information (PII)?

Yes
Logs contain IDs + counts only — never tokens, names, emails, or board/item content.

Is customer data segregated from the data of other customers (for example logically or physically)?

Yes
Every query/storage op filters by accountId from the verified JWT; Document DB is per-app; no cross-account path.

Privacy

Does the developer enforce multi-factor authentication on employees access to systems which may process customer data?

Yes
Solo developer, no employees; MFA/2FA enabled on all systems that touch customer data (GitHub, monday Dev Center, OpenAI, Cloudflare, GoDaddy).

Does the developer protect access to customer data based on the principle of least privilege?

Yes
Only 4 OAuth scopes; tokens in SecureStorage (encrypted); no human reads customer data — only app code runs the operations the customer authorized.

Reviews

No reviews yet.

Historical data

Installation history

We have data for December 28, 2024 onwards only. Collected sometime after 00:00 UTC daily.

Total number of installs

Change in total number of installs in last 1 day(s)

Compares the number of installs on each date with 1 days previously:

Max
Min
Current

Change in total number of installs in last 7 day(s)

Compares the number of installs on each date with 7 days previously:

Max
Min
Current

Change in total number of installs in last 30 day(s)

Compares the number of installs on each date with 30 days previously:

Max
Min
Current

Change in total number of installs in last 90 day(s)

Compares the number of installs on each date with 90 days previously:

Max
Min
Current

Change in total number of installs in last 180 day(s)

Compares the number of installs on each date with 180 days previously:

Max
Min
Current

Ratings history

Categories history

Each of the following is a yes/no answer, so the graphs show 1 for yes, and 0 for no.

In "Featured" category?

In "Editor's choice" category?

In "Trending this week" category?

App metadata

ID: 10001222App ID: 11274712Listing updated: July 21, 2026