Tabs
Provisioning is the only part of the console that writes to HubSpot. Every action asks for confirmation, is recorded in System activity, and updates the permission baseline so the change is never reported as drift.
| Control | What it does |
|---|---|
| New userTab | Create a HubSpot user in one or more portals. |
| TemplatesTab | Maintain role templates that map a job to HubSpot roles, permission sets and teams per portal. |
| MovesTab | Change a person's role, teams or portals. |
| OffboardTab | Remove a person from selected portals. |
New user
| Control | What it does |
|---|---|
| Use a templateTab | Pick a role template; the portals, roles and teams it defines are applied. |
| Choose manuallyTab | Pick portals, then a role and teams in each. |
| Set up userButton | Opens Create this user in HubSpot? Confirming creates the user in each selected portal and sends HubSpot's own invitation. |
Templates
| Control | What it does |
|---|---|
| New templateDialog | Name the template and choose the role, permission set and teams for each portal it applies to. The dialog is titled Edit template when opened from an existing row. |
| From baselineDialog | Opens Create templates from this baseline. Reviews the roles found in an imported baseline and proposes one template per role. Choose Create templates or Not now. |
| SaveButton | Saves edits to the template. |
| RemoveButton | Opens Delete this template? Users already created from the template are unaffected. |
Moves
| Control | What it does |
|---|---|
| Review and applyButton | Shows a before and after summary in Apply these changes in HubSpot? Confirming applies the role, team and portal changes and records User_Moved in the audit log. |
Offboard
- 1Search for the person and tick the portals to remove them from.
- 2Choose who receives their owned records in each portal. Removal is blocked until every record has a new owner.
- 3Select Remove access, then confirm in Remove this person from N portals.
If the person holds the Super admin role or a paid seat, FlowSentinel unassigns both automatically before removing them and records Removal_Blockers_Cleared. You do not need to change anything in HubSpot first.