What FlowSentinel reads
FlowSentinel reads the information it needs to govern access, and nothing else. Connecting is read-only by default: nothing is written back to HubSpot unless you run a provisioning or offboarding action yourself.
- Users: name, email, role, permission set, teams and whether the account is active or deactivated.
- Teams and roles: names and membership, used for drift comparison and access reviews.
- Sign-in history: who signed in and when, used for active-user trends and dormant access alerts.
- Account activity: who changed what and when, including the HubSpot record ID acted on. Available in full on Enterprise tiers.
- Property definitions and fill rates: which properties exist and what percentage of records use them. Never the values stored in those properties.
- Record counts: how many contacts, companies and deals each user owns or can access, keyed by user email. Used for offboarding handover, not analytics on the records themselves.
What FlowSentinel never stores
No contact, company or deal content is ever copied. That means no record names, email addresses, phone numbers, notes, property values or deal amounts. Where an activity entry mentions a record, only its HubSpot record ID is kept, so FlowSentinel can say who acted on it, not what it contained.
- No contact, company or deal names, emails, phone numbers or property values.
- No CRM record content of any kind, only record IDs and per-user counts.
- No HubSpot credentials in readable form. Portal tokens are encrypted at rest and only ever decrypted server-side during a scan.
How access is granted and removed
Access is granted by HubSpot when a super admin approves the FlowSentinel install, and the exact scopes are shown on the approval screen. Uninstalling the app in HubSpot ends access immediately, and FlowSentinel marks the portal as needing reauthorisation on its next scan.
Everything collected sits inside your organisation's estate and is only visible to members of that organisation, enforced on the server.