Overview
The HubSpot integration monitors your account’s user access, security configurations, and CRM data governance. LowerPlane syncs user data, team structures, security settings, and audit logs to support access reviews and compliance monitoring.Authentication
HubSpot uses OAuth 2.0 for authentication. When you connect, you’ll be redirected to HubSpot to authorize LowerPlane.Required Permissions (OAuth Scopes)
| Scope | What It Grants | Why LowerPlane Needs It |
|---|---|---|
crm.objects.contacts.read | Read contacts | Monitor CRM data governance and access patterns |
crm.objects.companies.read | Read companies | Inventory company records for data classification |
LowerPlane requests minimal read-only scopes. Additional data (users, teams, audit logs) is collected through HubSpot’s admin APIs which are available to all authenticated apps with portal access.
What LowerPlane Collects
Account Settings
Portal configuration, security settings, and account metadata
Users & Teams
User list with roles, teams, and access levels for access reviews
Roles & Permissions
Permission sets and role assignments for access governance
Security Settings
MFA enforcement, session policies, and login security configurations
Audit Logs
Activity logs for monitoring user actions and security events
CRM Data
Contact, company, and deal metadata for data governance (no PII content)
Workflows
Automation workflow inventory for change management auditing
API Usage
API call metrics for monitoring integration health and detecting anomalies
Critical System Access
HubSpot is automatically registered as a critical system in your access review program. All portal users are synced with their roles and permission sets, enabling:- Periodic user access reviews
- Offboarded employee detection (cross-referenced with HR data)
- Role-based access monitoring
- Permission set auditing
Security Tests
| Test | Severity | Description |
|---|---|---|
| User access should be valid | High | Verifies all HubSpot users are identified and mapped to HR records |
| Access should be removed for offboarded users | Critical | Detects terminated employees who still have active HubSpot accounts |
| MFA should be enabled | Critical | Checks MFA enforcement for all portal users |
| Password policy should be enforced | Medium | Validates password complexity requirements |