Portal Audit

Portal Audit setup guide

This guide covers installing Portal Audit in your HubSpot account, running your first audit, reading the report, and disconnecting the app. Portal Audit is read-only: it never changes anything in your HubSpot account.

Before you start

Install the app

  1. Click Install on the Portal Audit page (https://audit.thejonmartin.com) or in the HubSpot App Marketplace.
  2. Sign in to HubSpot if asked, then choose the account to connect.
  3. HubSpot shows the permissions Portal Audit asks for; the tables below explain each one. You can uncheck any optional permission; the related report sections will then show "not assessed" (see Why these permissions).
  4. Click Connect app. You land on a confirmation page that shows your portal ID and how many permissions were granted.

Permissions the app asks for

Required:

HubSpot dataScopeWhat the audit reads
AccountoauthAccount details: portal ID, time zone, currency, data hosting location
Contactscrm.objects.contacts.readRecord counts and field-completeness checks (counts only; no contact records are copied)
Companiescrm.objects.companies.readRecord counts and field-completeness checks
Dealscrm.objects.deals.readRecord counts, field completeness, deal pipelines and stages
Ticketscrm.objects.tickets.readRecord counts, field completeness, ticket pipelines and stages
Contactscrm.schemas.contacts.readProperty definitions (names, types, groups, usage flags)
Companiescrm.schemas.companies.readProperty definitions
Dealscrm.schemas.deals.readProperty definitions
Ticketscrm.schemas.tickets.readProperty definitions
Line itemscrm.objects.line_items.readRecord counts
Line itemscrm.schemas.line_items.readProperty definitions
Quotescrm.objects.quotes.readRecord counts
Quotescrm.schemas.quotes.readProperty definitions
Userscrm.objects.owners.readRecord owners (name, email, active/archived) to find unassigned or departed owners
Userssettings.users.readUsers and roles (name, email, role, super admin flag) for the access review
Userssettings.users.teams.readTeams and team membership
Segments (lists)crm.lists.readSegment names, types, sizes and last-updated dates
Account securityaccount-info.security.readLogin history, security activity and audit-log summaries (last 90 days); private-app API usage

Optional (you can uncheck these; HubSpot also leaves them out if your plan lacks the tool):

HubSpot dataScopeWhat the audit reads
FormsformsForm names, types and settings (submissions are not read)
Marketing emailmarketing-emailMarketing email names, states and settings (nothing is sent)
WorkflowsautomationWorkflow names, status, object type, enrollment settings and actions (no workflow is changed)
Marketing emailcontentMarketing email inventory when the marketing-email scope is not enough (some portals require content)
Custom objectscrm.objects.custom.readCustom object record counts and field completeness
Custom objectscrm.schemas.custom.readCustom object schemas and property definitions
Websitecms.domains.readConnected domains, to find the company website for the business profile

Why these permissions

Run your first audit

  1. After you install, we confirm your company profile with you: industry, company size and website. This tailors the best-practice checks to your business.
  2. We run the audit. A typical portal takes a few minutes; large portals can take longer because the app stays well under HubSpot's API rate limits.
  3. You receive the report as a PDF (and, on request, the underlying data as JSON or Markdown).
  4. Optional: a monthly audit on a day and time you choose, with month-over-month changes and fix-plan progress.

Read the report

Disconnect and uninstall

You can disconnect at any time, in either of two ways:

What happens to your data:

Get help

See Support, or email jon@thejonmartin.com.