Help centre

Getting started

How to connect to HubSpot

Connect your first portal, export a baseline user CSV if you want drift detection, and add further portals to the same estate.

Before you start

You need to be a super admin in the HubSpot portal you are connecting, and an administrator in FlowSentinel. Connecting is read-only by default: nothing is written back to HubSpot unless you later run a provisioning or offboarding action yourself.

  • A HubSpot super admin account for the portal.
  • An administrator sign-in for FlowSentinel.
  • Around ten minutes for the first sync to populate users and teams.

Connect your first portal

You connect by installing the FlowSentinel app from HubSpot. HubSpot manages the approval, and the access can be revoked from inside your portal at any time.

  1. 1Sign in to FlowSentinel and open Portals from the left-hand navigation.
  2. 2Select Connect with HubSpot.
  3. 3Choose the HubSpot portal you want to govern, review the requested scopes and approve the install.
  4. 4HubSpot returns you to the Portals page. The portal appears with a status of connected.
  5. 5Give the portal a name your team will recognise, for example the business unit or region it covers.
  6. 6Select Sync now on the portal card to pull users, teams and permission sets straight away.

If the install returns a warning naming missing scopes, your portal has not granted everything the app asked for. The connection still works, but the features relying on those scopes stay empty until the install is repeated with the scopes approved.

The access HubSpot issues is encrypted before it is stored and is never readable from the browser. Removing the portal in FlowSentinel, or uninstalling the app in HubSpot, ends the access.

What happens on the first sync

The first sync collects the people, teams, permission sets and property metadata for the portal. Expand the portal row on the Portals page to watch progress: it shows the last sync time, each feed's status and any features blocked by your HubSpot subscription tier.

Some feeds depend on your HubSpot plan. The full audit log is available on Enterprise only. Lower tiers still provide sign-in history, so active user trends and most alerts continue to work.

Export a baseline user CSV

A baseline is the approved picture of who should have what access. Drift detection compares live HubSpot permissions against it, field by field. This step is only required if you want drift detection; every other feature works without it.

  1. 1Open Drift from the left-hand navigation and select the portal.
  2. 2Choose Export baseline CSV. The file contains one row per user with their current role, teams, permission set and super admin flag.
  3. 3Review the file with whoever owns access approval and correct anything that should not be there.
  4. 4Return to Drift and select Import baseline, then upload the corrected file.
  5. 5From the next scan onward, any difference between HubSpot and this baseline is raised as drift.

Exporting the file straight back in without review sets today's access as approved, including anything that should not be. Review before you import.

Add a second portal

Every portal is connected the same way and sits in the same estate, so people, alerts and record access are compared across all of them.

  1. 1Sign out of HubSpot, or use a browser profile signed in to the second portal, so the install lands on the right account.
  2. 2In FlowSentinel, open Portals and select Connect with HubSpot again.
  3. 3Approve the install in the second portal and name it distinctly.
  4. 4Run Sync now, then export and import a baseline for that portal if you want drift detection there too.

Once two or more portals are connected, a person's page shows their access in each portal side by side, and security alerts cover people who hold access in more portals than they need.

Disconnecting or reconnecting

Uninstalling the app in HubSpot ends access immediately. FlowSentinel notices on its next scan, marks the portal as needing reauthorisation and offers a one-click reinstall. Snapshots, alerts and audit history are kept.

Disconnecting from the Portals page also asks HubSpot to revoke the token, so access ends at source rather than only in FlowSentinel.

Troubleshooting

  • The install failed with a scope error: your HubSpot user is not a super admin, or the portal declined a required scope. Ask a super admin to repeat the install.
  • Users are missing after a sync: the sync may still be running. Expand the portal row to check the feed status and the last sync time.
  • A feed shows as unavailable: this is usually a HubSpot subscription tier limit rather than a fault. The reason is named on the portal row.
  • Drift shows nothing: no baseline has been imported for that portal yet.