← Blog

FrameworkPortfolio

Kill criteria: a data-backed framework for sunsetting internal apps

Enterprises are excellent at launching internal software and nearly incapable of retiring it. The missing piece isn't courage — it's pre-agreed, data-backed criteria that make retirement a default outcome instead of a political fight.

July 21, 2026 · 6 min read

Illustration of a grid of app tiles under a magnifying glass

Why nothing ever dies

Every app in the portfolio has a sponsor who remembers why it was built, a team that maintains it, and a handful of users who'd notice. What no app has is a prosecutor. Retirement proposals arrive as opinions — "surely nobody uses this?" — and opinions lose to incumbency every time. Meanwhile the estate compounds: every zombie app is licenses, patching, an audit surface, an on-call burden, and an engineer who isn't building something people want. (The full picture: the shadow portfolio.)

The fix is to change the default. Don't ask "can anyone prove this app should die?" Ask "can this app meet the published survival criteria?" — and let the data answer.

The criteria

Set these once, publish them, and apply them quarterly. Numbers below are sane starting points — tune them to your estate, but tune them before the review, never during one.

TriggerThreshold (starting point)What it catches
Usage floorFewer than 20 distinct visitors/month for 2 consecutive quartersThe truly dead: apps kept alive by inertia and one bookmark.
Reach floorUnder 15% of the eligible audience monthlyApps that "have users" but lost their population — the workflow moved elsewhere.
Rating floorAverage below 2.5★ sustained for a quarter, with usage also decliningTools that are both disliked and being abandoned — fix-or-kill, not fix.
Trend triggerUsage down >50% year-over-year absent a replacement launchThe slow fade nobody notices quarter to quarter.
Duplication triggerAnother portfolio app serves the same job with ≥2× the usage and a higher ratingThe consolidation case that's obvious on one dashboard and invisible without it.

Breaching a criterion doesn't auto-delete anything — it moves the app into a justify-or-sunset queue where the owner gets one review cycle to make the case (seasonal usage, regulatory necessity, a captive critical audience). No case, no reprieve: the default is retirement. Defaults beat debates.

Run the funnel, not an execution

  1. Announce and freeze: retirement date published, no new features, feedback widget stays on — it will tell you fast if someone truly depends on a corner you missed.
  2. Redirect: point users at the successor tool or process; watch its usage absorb the load. If the load doesn't reappear anywhere, the workflow was already dead — the strongest confirmation you'll get.
  3. Read-only period: a quarter of data access without write access catches the archival stragglers cheaply.
  4. Archive and delete: data handled per retention policy; DNS, licenses, and on-call rotation actually cancelled — the savings are real only when this step happens.

The CFO frame

Present retirements the way finance hears them: each sunset app returns its run-rate — licenses, infrastructure, the maintenance fraction of an engineer — and reduces audit surface. A portfolio review that retires four apps a year typically self-funds the entire measurement program several times over. That's the pitch that turns "portfolio hygiene" from an engineering hobby into a budget line: the dashboard that names the zombies pays for itself with the first funeral.

Where Morvero fits: Morvero's executive command center sorts every product into a usage × sentiment quadrant — Fund / Fix / Niche / Retire? — with period-over-period movers and a printable board report. The kill criteria above read straight off it. Run the full process with the 30-day portfolio audit playbook, or start free.