Skip to main content

Beta Product documentation

HubSpot CRM Audit

Installation, permissions, audit operation, report delivery, deletion, and support—aligned with the current backend implementation.

Overview

HubSpot CRM Audit

HubSpot CRM Audit is a read-only application from MAN Digital. It inspects the quality and configuration of a connected HubSpot CRM, prioritises findings, and creates a downloadable PDF report. The PDF opens a protected delivery page for the detailed implementation workbook.

The app does not create, update, merge, archive, import, or delete HubSpot records. Its recommendations are advisory; your team decides what to change in HubSpot.

How reports are produced

The audit and report path does not use generative AI. Versioned, deterministic rules inspect the authorised HubSpot data, calculate findings and the health score, and generate the report from temporary report data. The same captured HubSpot evidence, audit timestamp, rule version, and settings produce the same result, and CRM data is not sent to an AI model by that path. An optional custom Breeze agent is a separate HubSpot AI feature.

Completion immediately starts and requires a confirmed purge of raw scan data and workflow checkpoints. Results are not served until that purge is confirmed. The detailed working-file stream never deletes persisted report content by itself. After the user verifies that the workbook was saved, a separate authenticated confirmation deletes the report content. An authenticated delete action or expiry of the 24-hour access window can also remove it. Expired content is never served, and the cleanup workflow retries any incomplete removal. The app retains no CRM record values, IDs, properties, finding details, or example links afterward. A non-content receipt containing status, timestamps, audit configuration, aggregate counts, purge reason, and purge timestamps remains.

The app's settings screen is a native HubSpot settings extension. It links to the HubSpot CMS audit workspace and the branded authorization service; the audit and report bytes are not processed inside the settings extension.

Start here

  1. Install the app and approve the requested permissions.
  2. Review the permissions, including optional audit modules.
  3. Run a sampled or full audit.
  4. Review the findings and download the PDF report.
Open HubSpot CRM Audit

What the audit covers

Every installation includes core checks for contacts, companies, deals, owners, tasks, meetings, calls, and relevant CRM property hygiene. Optional permissions requested by default extend the audit to supported assets such as leads, quotes, products, line items, goals, lists, campaigns, sequences, and workflows. Availability also depends on the connected HubSpot account's subscription and enabled products. The optional automation permission covers workflow inspection. The application restricts it to allowlisted read requests and blocks workflow create, update, enable, disable, and delete requests.

For help, use Get support. Use of the app is governed by MAN Digital's Privacy Policy and Terms of Service.

Installation

Install the app

You need permission to install apps in the HubSpot account you want to audit. A HubSpot Super Admin or a user with App Marketplace access can complete the installation.

Installation steps

  1. Open HubSpot CRM Audit.
  2. Select Connect HubSpot.
  3. Sign in to HubSpot if prompted, then choose the HubSpot account to audit.
  4. Review the requested permissions. Every authorization requests automation as an optional permission by default for workflow inspection. HubSpot can omit optional permissions that the selected account cannot grant.
  5. Tick HubSpot's authorisation acknowledgement when shown, then select Agree and continue or Connect app.
  6. HubSpot returns you to the audit workspace. Confirm that the correct account name and HubSpot portal ID are displayed before starting an audit.

Confirm the installation

A successful installation displays:

  • the connected HubSpot account name and portal ID;
  • a read-only connection notice;
  • the permissions granted to the app; and
  • the controls for a sampled or full audit.

If HubSpot reports incomplete core access, select Update authorization in the installed app's settings and approve all required scopes listed in Permissions. You do not need to uninstall or reinstall the app.

Authorization

Permissions

HubSpot CRM Audit requests OAuth installation access and every supported audit permission by default. The extended permissions are optional, including automation.sequences.read for sequences and automation for workflow inspection. The application restricts automation to allowlisted read requests and blocks workflow create, update, enable, disable, and delete requests.

Required access

ScopeWhy it is needed
oauthCompletes and maintains the authorised HubSpot connection.
crm.objects.contacts.readAudits contact completeness, hygiene, ownership, duplicate signals, and supported tasks, meetings, and calls associated with CRM records.
crm.objects.companies.readAudits company completeness, domains, ownership, and duplicate signals.
crm.objects.deals.readAudits deal completeness, pipelines, stages, ownership, and revenue signals.
crm.objects.owners.readChecks active and deactivated owner assignments.

These scopes are required for the core CRM audit.

The core audit also checks relevant CRM property definitions and values through the object read access above. Tasks, meetings, and calls are fetched through HubSpot's versioned CRM activity endpoints, which are authorised by the contact read scope for this app.

Product-dependent access

ScopeAdditional coverage
crm.objects.leads.readLeads
crm.objects.quotes.readQuotes
crm.objects.products.readProducts
crm.objects.line_items.readLine items
crm.objects.goals.readGoals
crm.lists.readLists
marketing.campaigns.readMarketing campaigns
automation.sequences.readSequences
automationWorkflows

HubSpot can omit an optional permission that the selected account cannot grant. The report names the affected module as unavailable instead of treating missing evidence as healthy. If a current optional permission is missing, use Update authorization for the existing installation; do not reinstall the app.

Workflow permission policy

automation.sequences.read covers sequences. automation covers workflow inspection. Both are optional and requested by default on every authorization. The application restricts automation to allowlisted workflow GET requests and blocks workflow create, update, enable, disable, and delete requests.

Object coverage and expansion

Object or areaCurrent supportAuthorization effect
Contacts, companies, deals, owners, activities, and property evidencePortal-wide audit; contact, company, and deal record checksCurrent required scopes; no authorization change
LeadsPortal-wide audit plus Lead workflow and Agent Tool record checksCurrent optional crm.objects.leads.read; use Update authorization only when the existing installation does not already have it
Quotes, products, line items, goals, lists, campaigns, sequences, and workflowsImplemented product-dependent audit modulesCurrent optional permissions listed above
TicketsNot included in this releaseHubSpot currently exposes only broad tickets, which covers retrieval plus ticket management and creation. CRM Audit does not declare or request it.
Additional custom, commerce, and service objectsNot pre-authorized; each object requires stable deterministic rules and verified product-tier behaviorA granular read permission is added only when its complete audit module ships

Adding checks within an already granted permission does not require reinstalling or reauthorizing the app. A genuinely new shipped permission uses Update authorization for the existing installation; the app is never reinstalled for a scope update.

Read-only guarantee

The application allowlists the HubSpot API paths and HTTP methods used by the audit. It does not request .write scopes and does not provide automatic remediation.

Audit run

Run an audit

Before starting, confirm that the account name and portal ID shown in the app match the HubSpot account you intend to inspect.

You can run another audit at any time while the portal remains connected. A new run reads the current HubSpot data and creates a new result; reinstalling the app is not required.

Choose the inspection boundary

  • Sampled inspects up to the selected number of records for each available object. Use it for a faster first review.
  • Full pages through all available records for each enabled object. Use it for final analysis and allow more time for large portals.

Set the stale-record threshold to match your operating cycle. The default is 90 days.

Start and monitor

  1. Select Sampled or Full.
  2. For a sampled audit, set the per-object limit.
  3. Set the stale-record threshold.
  4. Select Start read-only audit.
  5. Keep the page open or return later. The workflow persists progress and can resume safely while the audit is active.

The status shows the current object, completed modules, records inspected, and overall progress. Only one audit can run for a portal at a time.

You can cancel an active run. Cancellation stops future reads and does not change CRM records. Failed and cancelled run data expires within one hour. Completion immediately starts and requires a confirmed purge of raw CRM evidence and workflow checkpoints. If that purge does not complete, it is recorded and retried before the workflow treats completion as settled. Only the downloadable report data then remains temporarily.

Workflow automation

Use CRM Audit in HubSpot workflows

CRM Audit provides matching record-level actions for contact, company, deal, and Lead workflows. Each action applies deterministic checks to the enrolled record and returns structured outputs for branches, tasks, notifications, and later native HubSpot actions.

What each action checks

Workflow actionChecks assessed for every enrolled record
Contact
10 checks
Corrective data checks plus optional-phone and engagement advisories, engagement staleness, lifecycle-to-Deal consistency, and stage-aware Company expectations. The action also reports Company, Deal, Lead, Ticket, and Contract relationship presence.
Company
9 checks
Company name, domain, website, owner, contact association, last activity, industry, country, and country standardisation.
Deal
8 checks
Deal name, owner, amount, close date, overdue close date, company association, contact association, and stale open-deal activity.
Lead
3 checks
Lead owner, at least one associated Contact or Company, and pipeline-stage presence. The action does not infer business meaning from mutable or localized stage labels.

Where the actions are useful

Route clean and incomplete records

Branch on No corrective issues found. Contact advisories can remain visible without sending the record into a correction path. Use the priority tier when the service level should change by severity.

Assign an approved owner

Use the missing-owner output for contacts, companies, deals, or Leads. Add HubSpot's Edit record action only when the workflow logic establishes the correct owner; otherwise create a review task.

Complete lifecycle and segmentation fields

Use missing lifecycle stage, industry, country, and non-standard country outputs to route records into controlled standardisation paths using approved values.

Protect pipeline hygiene

Use missing amount, missing close date, overdue close date, and stale open-deal outputs to notify the owner or create a task. Never invent commercial values or dates.

Review relationship context

Use Company, Deal, Lead, Ticket, and Contract presence with its matching assessed flag. Missing Company is corrective only for sales-ready or revenue lifecycles; Opportunity or Customer without a Deal is a contradiction. Lead, Ticket, and Contract absence is context, not a universal failure. Edit record cannot repair an association.

Build a RevOps quality queue

Route by severity or recommended workflow action, then create an internal task or notification containing the issue, its impact, the recommendation, and the exact fix guidance.

Handle several issues in one execution

Use individual true/false flags in sequential branches. One deal can follow both a missing-owner path and a missing-close-date path without losing either issue.

Monitor without changing CRM

Use the outputs only for branches, tasks, and notifications. This is the safest rollout pattern before any property remediation is enabled.

Outputs available to later steps

Output groupWhat the workflow receivesTypical use
OutcomeCorrective pass/fail, checks assessed, and actionable issues foundCorrection branch and actionable-count routing
PriorityPriority tier and highest corrective severity; Contact advisories remain separateSLA, escalation, and ownership paths
ExplanationFirst issue, why it matters, recommended fix, summary, complete issue details, and stable finding codesTasks, notifications, and durable governance branches
Decision controlHuman-decision requirement and evidence required before a changeStop an unsafe automatic update and create a review path
Next stepRecommended workflow action, affected property, property internal name, Edit record applicability, exact fix instructions, and verification stepConfigure and recheck a deliberate downstream action
Contact RevOps contextCorrective and advisory counts/codes, engagement and next-activity status, lifecycle insight, relationship summary, and paired assessed/presence flagsPrioritise follow-up without exposing values, dates, content, or IDs
Issue flagsOne true/false output for every object-specific checkIndependent deterministic branches

Outputs belong to that workflow execution. They are not written to CRM properties unless an administrator explicitly adds and configures a later native HubSpot action.

Example: safe property update

  1. Create a contact-, company-, deal-, or Lead-based workflow and add the matching CRM Audit quality check.
  2. Add an If/then branch using a specific issue flag.
  3. In the true branch, add HubSpot's native Edit record action.
  4. Select the exact property and provide a business-approved value or a compatible value from a trusted workflow source.
  5. Stop for review when Human decision required is true or the required evidence is unavailable.
  6. Run the same quality check after the correction and follow How to verify the correction.
  7. In the false branch, continue without a change.
  8. Test representative records, inspect the outputs and workflow history, and only then turn the workflow on.

Example: review instead of automatic remediation

  1. Add the matching CRM Audit quality check.
  2. Branch on a stale-record or missing-association output.
  3. Create a native HubSpot task in the true branch.
  4. Include the record, first issue, operational impact, recommendation, and fix instructions where the selected HubSpot action supports output tokens.
  5. Let the record owner verify the information before updating, associating, or archiving anything.

Keep a customer list clean over time

  1. Keep the customer, ICP, pipeline, or governance list in HubSpot.
  2. Configure a scheduled workflow or explicit re-enrolment criteria for records that should be checked again.
  3. Run the matching deterministic CRM Audit action for each enrolled record.
  4. Finish the workflow when the record passes.
  5. When issues are found, branch by the specific issue and severity.
  6. Create an owner task, internal notification, or optional agent explanation.
  7. Apply a correction only through a separately configured HubSpot action with a trusted value and human review.
  8. Run the same CRM Audit check again to verify the correction.

Completed records do not automatically re-enrol. Test the exact schedule or re-enrolment rule in the target portal and prevent loops when a later update also matches the enrolment trigger. Use the deterministic action for large lists and reserve Run agent for cases where explanation or judgment adds value.

Governed remediation in HubSpot

CRM Audit Agent Tools return evidence, priority, required next steps, and branch-ready outputs without requesting CRM write scopes. Administrators can connect those outputs to deliberately configured native HubSpot actions after the record and proposed correction have been reviewed.

Keep the correction narrow: use a trusted value, require a person to approve the exact change immediately before mutation, and run the matching CRM Audit check again afterward. This gives teams an actionable workflow today while keeping the assessment layer deterministic and least-privilege.

Safe rollout checklist

  • Match the workflow object to the CRM Audit action object.
  • Start with manual enrollment or narrow test criteria and keep the workflow off until the test is reviewed.
  • Use true/false issue outputs for deterministic branches.
  • Never insert placeholders or guessed CRM values.
  • Avoid re-enrollment loops when a later update can satisfy the same enrollment criteria.
  • Provide a review path whenever the correct value cannot be established.
  • Review workflow history and HubSpot's Automation Insights after launch.

Availability and monitoring

The portal needs the app installed, the matching CRM object read permission, and access to HubSpot workflows. The CRM Audit quality checks do not require CRM write scopes. Any later record change is performed by a native HubSpot action under the portal administrator's workflow configuration and permissions.

Use Settings > Integrations > Connected Apps > Connection insights > Automation Insights to review active workflows, action use, enrollments, and unused workflow actions. Use the individual workflow's history to inspect a specific record execution.

If a record disappears before evaluation, the action returns Record unavailable, prevents a property-update recommendation, and allows the workflow to continue into a review path. Invalid callbacks are rejected. A temporary HubSpot or application dependency failure remains visible as a workflow error instead of silently reporting a clean record.

Processing boundary

The callback verifies HubSpot's request signature and binds the execution to the connected portal and required object permission. Responses are private and no-store. Record values are processed for that execution and are not written to audit runs, report files, analytics, or application logs.

AI Agent Tools

Use CRM Audit Agent Tools in HubSpot

CRM Audit separates a portal-wide assessment from ongoing record hygiene. The application runs the full deterministic audit and creates the temporary PDF report and detailed workbook. Four HubSpot Agent Tools assess one selected Contact, Company, Deal, or Lead at a time.

The full audit is the right path for a complete CRM snapshot. Agent Tools are the right path for focused follow-up inside Agent Builder or a HubSpot workflow. The released tools are read-only and do not start a full audit, change CRM records, or retain a second audit archive.

Four read-only tools available now

Agent ToolDeterministic checksInput boundary
Check contact data qualityCorrective data checks plus optional-phone advisories, engagement and next-activity timing, lifecycle-to-Deal consistency, and Company, Deal, Lead, Ticket, and Contract relationship presenceOne positive numeric Contact record ID; optional engagement stale threshold
Check company data qualityName, domain, website, owner, Contact association, last activity, industry, country, and country standardisationOne positive numeric Company record ID; optional stale threshold
Check deal data qualityName, owner, amount, close date, overdue close date, Company association, Contact association, and stale open-deal activityOne positive numeric Deal record ID; optional stale threshold
Check lead data qualityOwner, at least one associated Contact or Company, and pipeline-stage presenceOne positive numeric Lead record ID

The Contact check defaults to a 180-day engagement stale threshold and does not use record modification time as a substitute for engagement. Company and Deal checks keep their 180-day record thresholds. The Lead check does not infer business meaning from mutable or localised pipeline-stage labels.

Each execution separates corrective findings from advisory observations. Missing phone is optional enrichment: it remains visible as CNT-002 but does not fail the Contact check, recommend an edit, or reduce the CRM Health Score. The PDF/workbook can still list it as optional enrichment. Contact engagement, lifecycle, next-activity, and relationship outputs never include CRM values, association IDs, activity content, or timestamps.

Give the agent only the access it needs

An agent does not automatically receive CRM data merely because an Agent Tool is installed. Give the agent an approved HubSpot record-read or search tool when it needs to resolve a record, then pass the resulting positive numeric record ID to the matching CRM Audit tool.

Do not ask an agent to guess a record ID from a name, email address, domain, or deal label. Keep each agent role-bounded and add only the tools required for its job.

AI agents available with the app

Role-bounded stewards for the revenue lifecycle

CRM Audit uses one deterministic quality layer and several role-bounded Breeze agents. These are not differently named copies of one universal HubSpot administrator. Each agent has a narrow operating remit, receives only the tools it needs, and routes unknown or consequential values to the accountable person.

The current Marketplace release unit is the CRM Audit app and its Agent Tools. A role-specific agent is a HubSpot Breeze configuration that uses those installed tools. HubSpot reviews Agent Tools separately from publishing a custom agent in the Breeze Marketplace, so a portal-built agent is not described as publicly installable until HubSpot approves that distribution path.

Customer Revenue Data Steward

Reviews one explicitly selected Company, Contact, Deal, or Lead that affects a customer or revenue handoff.

Marketing Operations Steward

Improves identity, ownership, engagement, lifecycle, segmentation, and relationship hygiene.

Sales Operations Steward

Prioritises Deal pipeline completeness, close-date and activity risk, Lead routing, ownership, and associations.

Customer Operations Steward

Supports onboarding, service routing, renewals, customer-list governance, and clean operating handoffs.

Customer Success Steward

Reviews customer Companies, stakeholder Contacts, Deal handoffs, and relevant relationship coverage.

RevOps Steward

Coordinates cross-object exceptions, lifecycle and pipeline handoffs, and accountable escalation across teams.

Revenue Data Steward

Connects product catalogue, line-item, quote, invoice, subscription, contract, and commercial-association quality.

Customer Revenue Data Steward

MAN Digital runs one named customer proof on the shared deterministic tools rather than a universal HubSpot administrator. The Customer Revenue Data Steward checks one explicitly selected Company, Contact, Deal, or Lead at a time, explains the revenue and handoff risk, identifies required evidence, and proposes a human-owned next step.

Keep high-volume assessment in workflow actions and invoke the agent only for an exception that benefits from explanation, prioritisation, or an ambiguous handoff. Missing phone remains optional enrichment. Ticket and Contract signals report relationship presence only, never status or content.

Sales Operations Steward

Uses Deal and Lead tools for pipeline hygiene, ownership, associations, and routing completeness. It routes uncertain commercial values to the owner or manager and never advances a stage or invents an amount or date.

Marketing Operations Steward

Uses Contact and Company tools on customer, ICP, campaign, or governance lists for identity, ownership, engagement recency, next activity, lifecycle-to-Deal consistency, relationship context, industry, and country. Missing phone stays optional unless the agreed motion requires calls.

Customer Operations Steward

Maintains operating customer records across onboarding, service routing, renewal preparation, and customer-list governance. It uses Deal context only for an explicitly selected commercial handoff.

Customer Success Steward

Reviews a customer Company, stakeholder Contacts, the Deal handoff, and bounded Ticket or Contract relationship presence. Presence does not reveal status or content, and Ticket field checks are not part of this release.

RevOps Steward

Coordinates Contact, Company, Lead, and Deal exceptions without becoming an unrestricted portal administrator. It cannot change CRM records, workflows, lists, settings, permissions, or portal configuration.

Revenue Data Steward

Targets Products, Line items, Quotes, Invoices, Subscriptions, Contracts, and their commercial associations so commercial records can be reviewed as one revenue chain.

Keep a governed list clean over time

  1. Select the HubSpot list or filters that define the governed records.
  2. Configure and test a schedule or explicit re-enrolment rule.
  3. Run the matching deterministic CRM Audit action for each record.
  4. End the clean branch and route issue records by stable finding code, issue flag, and severity.
  5. Create a task, notification, or optional role-bounded agent explanation.
  6. Apply only a reviewed correction with a trusted value.
  7. Run the deterministic check again to verify the finding cleared.

HubSpot records do not re-enrol by default merely because the workflow ran before. Test the exact recurrence and prevent update loops. Use the deterministic action for large lists; reserve Run agent for cases where explanation or judgment adds value. HubSpot currently limits that workflow action to 500 executions per day.

Evidence, human review, and verification

Record checks return stable finding codes, whether a human decision is required, the evidence required before a change, and the verification step. They do not return a guessed replacement value.

The Agent Tools emit humanDecisionRequired and branch-ready evidence. Administrators can connect the reviewed result to a narrow native HubSpot action; CRM Audit does not request CRM write scopes or silently update the record.

AI and data boundary

The portal-wide audit, PDF, workbook, workflow actions, and Agent Tool callbacks use deterministic application code and do not call an LLM. A custom HubSpot agent is a separate HubSpot AI feature. HubSpot administrators control AI access, the tools granted to the agent, and the data supplied to it.

Invoking an agent sends the selected tool inputs and outputs to HubSpot's agent environment, whose history and retention are controlled by HubSpot and the portal administrator. If an administrator sends findings to tasks, workflow history, Agent Inbox, or a customer-controlled Sheet, that chosen destination has its own retention policy. CRM Audit does not create a second list or audit archive for recurring governance.

Marketplace availability

HubSpot's Agent Tool review requires the production app ID, a successful developer-project build, every Agent Tool UID, and a video showing successful test runs. CRM Audit will submit the four released read-only tools together so customers can add them to their own role-bounded agents after installation.

Publishing the app and Agent Tools does not automatically publish role-specific Breeze configurations in the Marketplace. Until HubSpot separately accepts and approves those agent listings, these agents are documented as configuration patterns, not one-click Marketplace agents.

Add and test the tools

  1. Confirm CRM Audit is installed and the portal has the matching object read permission. Use Update authorization only when an existing installation is missing a required object permission.
  2. In Breeze Studio > Agent Builder, create or open an inactive test agent.
  3. In What this agent can do, choose Add tool.
  4. Under HubSpot, add only the required HubSpot CRM Audit tools.
  5. Add an approved HubSpot record-read or search tool if the agent must resolve a record before it can pass the numeric ID.
  6. Test direct and goal-based prompts, parameter extraction, and tool sequences with HubSpot's Developer Tool Testing Agent.
  7. Test a valid synthetic record, an incomplete record, a missing or deleted record, a missing-permission case, and a temporary dependency failure before publishing the agent.

See HubSpot's Agent Tools overview, Agent Tools reference, Breeze Studio agent guide, and Run agent workflow guide.

Results

Results and report delivery

A completed audit presents the evidence it assessed, the CRM health score, severity totals, object coverage, assessed health areas, and ranked aggregate priorities.

Interpret the results

  • Health score summarises the assessed areas and evidence coverage.
  • Priorities rank the findings with the greatest expected operational impact.
  • Severity groups findings as critical, high, medium, or low.
  • Object coverage shows how many records were inspected for each object.

Findings are recommendations, not automatic changes. Validate them against your CRM governance and business process before remediation.

Download the PDF report

Select Download PDF report on a completed run. This is the only report download action shown in the results UI. The protected export endpoint checks the signed session, portal ownership, and run status before rendering the A4 PDF in memory. The app does not archive the PDF.

The PDF opens a protected delivery page for the detailed implementation workbook. That page verifies the same signed HubSpot portal session before it shows the explicit Download working file action. The PDF never links directly to the one-time workbook stream, and there is no separate workbook action on the results page.

Detailed implementation workbook

The workbook contains summary, evidence, and review-focused tabs. Personal email and phone matching keys are masked by default, and spreadsheet formula prefixes in CRM-controlled text are neutralised.

The XLSX file is generated on demand in a private temporary location, streamed with no-store caching, and deleted from temporary storage after completion, failure, or client cancellation. Store downloaded reports according to your organisation's security and retention policies.

The working-file stream returns an opaque delivery token but never deletes persisted report content. Supported Chromium browsers pipe the response directly to a user-selected local file; other browsers use a compatibility download path. After the complete file is saved, the user selects the separate confirmation action. Only that authenticated confirmation atomically deletes the remaining report content. If the stream is interrupted or the save cannot be verified, the temporary file is removed and report content remains available for another authenticated attempt. The token is captured before body consumption. If claim release fails, the page retains it for a secure-reset retry instead of starting a competing export; a bounded lease supplies final recovery. Report access expires 24 hours after completion, expired content is never served, and the cleanup workflow retries removal if necessary. Delete audit data now provides a separate confirmed deletion path.

After deletion, the run remains visible only as a non-content receipt with status, timestamps, audit configuration, aggregate counts, and purge timestamps. It contains no CRM record values, record IDs, properties, finding details, example links, or generated files. The PDF link cannot recreate the workbook after report content is purged.

Security

Security and data

HubSpot CRM Audit is designed as a tenant-isolated, read-only application.

Controls

  • HubSpot access and refresh tokens are encrypted with AES-256-GCM before database storage.
  • The installing user's email address is not stored.
  • OAuth state and application sessions are signed; session cookies are HTTP-only, secure in production, and use a restrictive SameSite policy.
  • Every audit, status, cancellation, result, and export lookup is bound to the HubSpot portal ID from the verified session.
  • HubSpot requests are restricted to allowlisted read endpoints and methods.
  • Report generation is deterministic code; CRM data is not sent to a generative AI or large-language-model service.
  • Secrets remain in server-side deployment settings and are not sent to the browser or committed to the repository.
  • Generated XLSX files use private temporary storage and Cache-Control: private, no-store.
  • Database tables use row-level security and are not available through the public Supabase API roles.

Data processed

The app reads only the CRM properties needed for the selected audit modules. While an audit is running, it temporarily stores progress, resumable checkpoints, and the CRM evidence required to finish the selected scan.

When an audit reaches completion:

  • completion immediately starts and requires a confirmed purge of raw CRM records and workflow checkpoints; an incomplete purge is recorded and retried before the workflow treats completion as settled;
  • the report data remains available until saved-file delivery is explicitly confirmed, an authenticated user deletes it, or the 24-hour access window expires;
  • selecting Delete audit data now removes the remaining report data immediately;
  • failed and cancelled run data expires within one hour.

The durable audit workflow waits until the run's deletion deadline and then invokes the database retention function independently of customer traffic. An authenticated daily maintenance job and PostgreSQL pg_cron, when available, provide additional cleanup paths.

A separate database watchdog treats a queued, running, or cancelling audit as failed after six hours without progress and purges its CRM-derived data. Normal large audits update their progress timestamp on every HubSpot page.

Database write guards serialize audit child writes with terminal cleanup. A late workflow step cannot recreate CRM-derived rows after a run has become terminal, and repeated cleanup removes terminal child rows idempotently.

After deletion, the app keeps only a non-content audit receipt: the run ID, portal boundary, status, timestamps, aggregate counts, and purge timestamps. It does not retain CRM record values, record IDs, properties, finding details, example links, or workbook files in the active database.

The HubSpot connection is a separate record. While it remains active, it holds the portal ID and name, granted scopes, encrypted OAuth credentials, status and session timestamps, and the numeric HubSpot user ID required by HubSpot's Sequences API. It stores no installer email. Disconnecting clears the credentials, user ID, portal display name, and granted scopes and rotates the session version.

The app does not write audit results or recommendations back to HubSpot. Downloaded reports leave the application environment and become the customer's responsibility.

Backups and deletion

The time limits above describe deletion from active application systems. Provider backups may retain a deleted database version for the provider's configured backup window before automatic expiry. They are not used to serve the application or customer reports.

Uninstalling the app revokes future HubSpot access. The same automatic retention limits continue to apply, so no separate request is required to remove report content from active systems. For privacy questions, contact hello@man.digital and include only the HubSpot portal ID. Do not send OAuth tokens, credentials, or exported CRM data by email.

Also review the MAN Digital Terms of Service.

Access removal

Disconnect and uninstall

Uninstall the app from HubSpot when it should no longer access the account. This revokes its OAuth access and stops future CRM reads.

Uninstall from HubSpot

  1. In HubSpot, select the Settings icon.
  2. In the left sidebar, go to Integrations > Connected Apps.
  3. Find HubSpot CRM Audit.
  4. Select Actions > Uninstall.
  5. Type uninstall when HubSpot asks for confirmation, then select Uninstall.

HubSpot administrators can also manage installation approval and user access from the Connected Apps area. See HubSpot's current HubSpot uninstall instructions if the navigation differs.

After uninstalling

  • New audits and HubSpot reads will no longer work for that portal.
  • HubSpot revokes the app's upstream OAuth access immediately. The audit service checks active refresh credentials through a bounded scheduled job. When HubSpot rejects the revoked credential, it marks the local installation disconnected, clears both encrypted token fields, the numeric installer user ID, portal display name, and granted scopes, and rotates the session version.
  • Previously downloaded XLSX files are not controlled by the app; remove them from your own systems if required.
  • Each completed audit immediately starts and requires a confirmed raw-data purge. An incomplete purge is retried before completion is treated as settled.
  • Any remaining report access expires after 24 hours. Content is removed sooner only after explicit saved-file confirmation or Delete audit data now; the cleanup workflow retries expired-content removal when necessary.
  • Non-content audit receipts do not contain CRM record values, IDs, properties, finding details, or example links.

The app can be installed again later by an authorised HubSpot user.

Help

Support

Email hello@man.digital for installation, access, audit, or export support.

Include

  • the HubSpot portal ID shown in the audit workspace;
  • the audit run ID, when available;
  • the time of the issue and your time zone;
  • the step you were completing; and
  • the visible error message or a screenshot with personal CRM data removed.

Useful checks

  1. Confirm the correct HubSpot account is connected.
  2. Confirm the required permissions in Permissions were granted.
  3. Check whether another audit is already active for the portal.
  4. Retry after reconnecting if the app reports that the session expired.

For privacy or deletion requests, include the HubSpot portal ID and clearly state the request. MAN Digital's Privacy Policy and Terms of Service apply.