Overview
HubSpot CRM Audit
HubSpot CRM Audit is a read-only application from MAN Digital. It inspects the quality and configuration of a connected HubSpot CRM, prioritises findings, and creates a downloadable PDF report. The PDF opens a protected delivery page for the detailed implementation workbook.
The app does not create, update, merge, archive, import, or delete HubSpot records. Its recommendations are advisory; your team decides what to change in HubSpot.
How reports are produced
The app does not use generative AI. Versioned, deterministic rules inspect the authorised HubSpot data, calculate findings and the health score, and generate the report from temporary report data. The same input and audit settings produce the same result, and CRM data is not sent to an AI model.
Completion immediately starts and requires a confirmed purge of raw scan data and workflow checkpoints. Results are not served until that purge is confirmed. The detailed working-file stream never deletes persisted report content by itself. After the user verifies that the workbook was saved, a separate authenticated confirmation deletes the report content. An authenticated delete action or expiry of the 24-hour access window can also remove it. Expired content is never served, and the cleanup workflow retries any incomplete removal. The app retains no CRM record values, IDs, properties, finding details, or example links afterward. A non-content receipt containing status, timestamps, audit configuration, aggregate counts, purge reason, and purge timestamps remains.
The app's settings screen is a native HubSpot settings extension. It links to the HubSpot CMS audit workspace and the branded authorization service; the audit and report bytes are not processed inside the settings extension.
Start here
- Install the app and approve the requested read-only access.
- Review the permissions, including optional audit modules.
- Run a sampled or full audit.
- Review the findings and download the PDF report.
What the audit covers
Every installation includes core checks for contacts, companies, deals, owners, tasks, meetings, calls, and relevant CRM property hygiene. Optional product-dependent permissions extend the audit to supported assets such as leads, quotes, products, line items, goals, lists, campaigns, sequences, and workflows. Availability also depends on the connected HubSpot account's subscription and enabled products. HubSpot grants automation for workflow access; this application uses it read-only and blocks workflow create, update, and delete requests.
For help, use Get support. Use of the app is governed by MAN Digital's Privacy Policy and Terms of Service.
Installation
Install the app
You need permission to install apps in the HubSpot account you want to audit. A HubSpot Super Admin or a user with App Marketplace access can complete the installation.
Installation steps
- Open HubSpot CRM Audit.
- Select Connect HubSpot.
- Sign in to HubSpot if prompted, then choose the HubSpot account to audit.
- Review the required and optional permissions. The optional request includes HubSpot's
automationpermission for workflow inspection. - Tick HubSpot's authorisation acknowledgement when shown, then select Agree and continue or Connect app.
- HubSpot returns you to the audit workspace. Confirm that the correct account name and HubSpot portal ID are displayed before starting an audit.
Confirm the installation
A successful installation displays:
- the connected HubSpot account name and portal ID;
- a read-only connection notice;
- the permissions granted to the app; and
- the controls for a sampled or full audit.
If HubSpot reports incomplete core access, reconnect the app and approve all required scopes listed in Permissions.
Authorization
Permissions
HubSpot CRM Audit requests OAuth installation access, required core scopes, and every supported product-dependent scope as optional. This includes HubSpot's broader automation permission for workflow access. The application uses it read-only and blocks workflow create, update, and delete requests.
Required access
| Scope | Why it is needed |
|---|---|
oauth | Completes and maintains the authorised HubSpot connection. |
crm.objects.contacts.read | Audits contact completeness, hygiene, ownership, duplicate signals, and supported tasks, meetings, and calls associated with CRM records. |
crm.objects.companies.read | Audits company completeness, domains, ownership, and duplicate signals. |
crm.objects.deals.read | Audits deal completeness, pipelines, stages, ownership, and revenue signals. |
crm.objects.owners.read | Checks active and deactivated owner assignments. |
These scopes are required for the core CRM audit.
The core audit also checks relevant CRM property definitions and values through the object read access above. Tasks, meetings, and calls are fetched through HubSpot's versioned CRM activity endpoints, which are authorised by the contact read scope for this app.
Optional access
| Scope | Additional coverage |
|---|---|
crm.objects.leads.read | Leads |
crm.objects.quotes.read | Quotes |
crm.objects.products.read | Products |
crm.objects.line_items.read | Line items |
crm.objects.goals.read | Goals |
crm.lists.read | Lists |
marketing.campaigns.read | Marketing campaigns |
automation.sequences.read | Sequences |
automation | Workflows |
Declining an optional scope does not block the core audit. The relevant extended module will be omitted when its scope or HubSpot product is unavailable.
Workflow permission policy
HubSpot grants the broad automation permission for workflow access. It is optional in the default authorization request so accounts without the relevant entitlement can still install. This application uses automation read-only: its allowlist blocks workflow create, update, enable, disable, and delete requests.
Read-only guarantee
The application allowlists the HubSpot API paths and HTTP methods used by the audit. It does not request .write scopes and does not provide automatic remediation.
Audit run
Run an audit
Before starting, confirm that the account name and portal ID shown in the app match the HubSpot account you intend to inspect.
You can run another audit at any time while the portal remains connected. A new run reads the current HubSpot data and creates a new result; reinstalling the app is not required.
Choose the inspection boundary
- Sampled inspects up to the selected number of records for each available object. Use it for a faster first review.
- Full pages through all available records for each enabled object. Use it for final analysis and allow more time for large portals.
Set the stale-record threshold to match your operating cycle. The default is 90 days.
Start and monitor
- Select Sampled or Full.
- For a sampled audit, set the per-object limit.
- Set the stale-record threshold.
- Select Start read-only audit.
- Keep the page open or return later. The workflow persists progress and can resume safely while the audit is active.
The status shows the current object, completed modules, records inspected, and overall progress. Only one audit can run for a portal at a time.
You can cancel an active run. Cancellation stops future reads and does not change CRM records. Failed and cancelled run data expires within one hour. Completion immediately starts and requires a confirmed purge of raw CRM evidence and workflow checkpoints. If that purge does not complete, it is recorded and retried before the workflow treats completion as settled. Only the downloadable report data then remains temporarily.
Results
Results and report delivery
A completed audit presents the evidence it assessed, the CRM health score, severity totals, object coverage, assessed health areas, and ranked aggregate priorities.
Interpret the results
- Health score summarises the assessed areas and evidence coverage.
- Priorities rank the findings with the greatest expected operational impact.
- Severity groups findings as critical, high, medium, or low.
- Object coverage shows how many records were inspected for each object.
Findings are recommendations, not automatic changes. Validate them against your CRM governance and business process before remediation.
Download the PDF report
Select Download PDF report on a completed run. This is the only report download action shown in the results UI. The protected export endpoint checks the signed session, portal ownership, and run status before rendering the A4 PDF in memory. The app does not archive the PDF.
The PDF opens a protected delivery page for the detailed implementation workbook. That page verifies the same signed HubSpot portal session before it shows the explicit Download working file action. The PDF never links directly to the one-time workbook stream, and there is no separate workbook action on the results page.
Detailed implementation workbook
The workbook contains summary, evidence, and review-focused tabs. Personal email and phone matching keys are masked by default, and spreadsheet formula prefixes in CRM-controlled text are neutralised.
The XLSX file is generated on demand in a private temporary location, streamed with no-store caching, and deleted from temporary storage after completion, failure, or client cancellation. Store downloaded reports according to your organisation's security and retention policies.
The working-file stream returns an opaque delivery token but never deletes persisted report content. Supported Chromium browsers pipe the response directly to a user-selected local file; other browsers use a compatibility download path. After the complete file is saved, the user selects the separate confirmation action. Only that authenticated confirmation atomically deletes the remaining report content. If the stream is interrupted or the save cannot be verified, the temporary file is removed and report content remains available for another authenticated attempt. The token is captured before body consumption. If claim release fails, the page retains it for a secure-reset retry instead of starting a competing export; a bounded lease supplies final recovery. Report access expires 24 hours after completion, expired content is never served, and the cleanup workflow retries removal if necessary. Delete audit data now provides a separate confirmed deletion path.
After deletion, the run remains visible only as a non-content receipt with status, timestamps, audit configuration, aggregate counts, and purge timestamps. It contains no CRM record values, record IDs, properties, finding details, example links, or generated files. The PDF link cannot recreate the workbook after report content is purged.
Security
Security and data
HubSpot CRM Audit is designed as a tenant-isolated, read-only application.
Controls
- HubSpot access and refresh tokens are encrypted with AES-256-GCM before database storage.
- The installing user's email address is not stored.
- OAuth state and application sessions are signed; session cookies are HTTP-only, secure in production, and use a restrictive SameSite policy.
- Every audit, status, cancellation, result, and export lookup is bound to the HubSpot portal ID from the verified session.
- HubSpot requests are restricted to allowlisted read endpoints and methods.
- Report generation is deterministic code; CRM data is not sent to a generative AI or large-language-model service.
- Secrets remain in server-side deployment settings and are not sent to the browser or committed to the repository.
- Generated XLSX files use private temporary storage and
Cache-Control: private, no-store. - Database tables use row-level security and are not available through the public Supabase API roles.
Data processed
The app reads only the CRM properties needed for the selected audit modules. While an audit is running, it temporarily stores progress, resumable checkpoints, and the CRM evidence required to finish the selected scan.
When an audit reaches completion:
- completion immediately starts and requires a confirmed purge of raw CRM records and workflow checkpoints; an incomplete purge is recorded and retried before the workflow treats completion as settled;
- the report data remains available until saved-file delivery is explicitly confirmed, an authenticated user deletes it, or the 24-hour access window expires;
- selecting Delete audit data now removes the remaining report data immediately;
- failed and cancelled run data expires within one hour.
The durable audit workflow waits until the run's deletion deadline and then invokes the database retention function independently of customer traffic. An authenticated daily maintenance job and PostgreSQL pg_cron, when available, provide additional cleanup paths.
A separate database watchdog treats a queued, running, or cancelling audit as failed after six hours without progress and purges its CRM-derived data. Normal large audits update their progress timestamp on every HubSpot page.
Database write guards serialize audit child writes with terminal cleanup. A late workflow step cannot recreate CRM-derived rows after a run has become terminal, and repeated cleanup removes terminal child rows idempotently.
After deletion, the app keeps only a non-content audit receipt: the run ID, portal boundary, status, timestamps, aggregate counts, and purge timestamps. It does not retain CRM record values, record IDs, properties, finding details, example links, or workbook files in the active database.
The HubSpot connection is a separate record. While it remains active, it holds the portal ID and name, granted scopes, encrypted OAuth credentials, status and session timestamps, and the numeric HubSpot user ID required by HubSpot's Sequences API. It stores no installer email. Disconnecting clears the credentials, user ID, portal display name, and granted scopes and rotates the session version.
The app does not write audit results or recommendations back to HubSpot. Downloaded reports leave the application environment and become the customer's responsibility.
Backups and deletion
The time limits above describe deletion from active application systems. Provider backups may retain a deleted database version for the provider's configured backup window before automatic expiry. They are not used to serve the application or customer reports.
Uninstalling the app revokes future HubSpot access. The same automatic retention limits continue to apply, so no separate request is required to remove report content from active systems. For privacy questions, contact hello@man.digital and include only the HubSpot portal ID. Do not send OAuth tokens, credentials, or exported CRM data by email.
Also review the MAN Digital Terms of Service.
Access removal
Disconnect and uninstall
Uninstall the app from HubSpot when it should no longer access the account. This revokes its OAuth access and stops future CRM reads.
Uninstall from HubSpot
- In HubSpot, select the Settings icon.
- In the left sidebar, go to Integrations > Connected Apps.
- Find HubSpot CRM Audit.
- Select Actions > Uninstall.
- Type
uninstallwhen HubSpot asks for confirmation, then select Uninstall.
HubSpot administrators can also manage installation approval and user access from the Connected Apps area. See HubSpot's current HubSpot uninstall instructions if the navigation differs.
After uninstalling
- New audits and HubSpot reads will no longer work for that portal.
- HubSpot revokes the app's upstream OAuth access immediately. The audit service checks active refresh credentials through a bounded scheduled job. When HubSpot rejects the revoked credential, it marks the local installation disconnected, clears both encrypted token fields, the numeric installer user ID, portal display name, and granted scopes, and rotates the session version.
- Previously downloaded XLSX files are not controlled by the app; remove them from your own systems if required.
- Each completed audit immediately starts and requires a confirmed raw-data purge. An incomplete purge is retried before completion is treated as settled.
- Any remaining report access expires after 24 hours. Content is removed sooner only after explicit saved-file confirmation or Delete audit data now; the cleanup workflow retries expired-content removal when necessary.
- Non-content audit receipts do not contain CRM record values, IDs, properties, finding details, or example links.
The app can be installed again later by an authorised HubSpot user.
Help
Support
Email hello@man.digital for installation, access, audit, or export support.
Include
- the HubSpot portal ID shown in the audit workspace;
- the audit run ID, when available;
- the time of the issue and your time zone;
- the step you were completing; and
- the visible error message or a screenshot with personal CRM data removed.
Useful checks
- Confirm the correct HubSpot account is connected.
- Confirm the required permissions in Permissions were granted.
- Check whether another audit is already active for the portal.
- Retry after reconnecting if the app reports that the session expired.
For privacy or deletion requests, include the HubSpot portal ID and clearly state the request. MAN Digital's Privacy Policy and Terms of Service apply.