Help centre

Governance

Security

Work security alerts, review role telemetry, import the permission baseline, inspect users and permission sets, and read sign-in history.

Tabs

ControlWhat it does
AlertsTabOpen security alerts with severity, the person and portal involved and the proposed remediation.
Role telemetryTabWhich capabilities each role actually uses, so over-provisioned roles stand out.
BaselineTabUpload and review the approved permission baseline used by drift detection.
UsersTabLatest permission snapshot per user with super admin flags.
Permission setsTabHubSpot roles and permission sets with member counts. Show all roles expands the list.
LoginsTabHubSpot sign-in history for the selected portals.

Working an alert

ControlWhat it does
Show all alertsButtonIncludes resolved and dismissed alerts in the list.
Approve & executeButtonAdministrators only. Opens Execute this remediation. Confirming applies the proposed change in HubSpot, for example moving a user to the quarantine role, and records it as a sanctioned action so it does not show as drift.
DismissButtonOpens the Dismiss alert dialog. Enter a reason; the alert is closed and the reason kept for audit.
Add to baselineButtonAdministrators only, on baseline deviation and super admin not in baseline alerts. Opens Accept this access as the approved baseline. Confirming updates or adds the person's row in the active baseline to match the role HubSpot currently shows, closes the alert and records the change in the audit trail. Nothing is written to HubSpot.
Notify userButtonOpens Email this person about two-step verification. Sends a branded reminder to the HubSpot user named in the alert.

Baseline tab

The baseline is the list of approved users and their roles for a portal. It comes from a HubSpot user export, so FlowSentinel never guesses who should have access.

  1. 1In HubSpot, open Settings, then Users & Teams under Account management.
  2. 2Click Actions at the top right of the Users tab, then Export all users.
  3. 3Leave the file format as CSV and click Export. HubSpot sends the file to your notifications centre and by email.
  4. 4In FlowSentinel, open Security, then the Baseline tab. Find the portal the export belongs to and click Upload CSV next to its name.
  5. 5Choose the downloaded file. No edits are needed. The import replaces the active baseline for that portal.
Video walkthrough: exporting your users from HubSpot.
HubSpot settings with Users & Teams selected and the Actions button visible
HubSpot, Settings, Users & Teams.
The Actions menu open with Export all users highlighted
Actions, then Export all users.
The HubSpot export dialog with CSV selected
Keep CSV and click Export.
FlowSentinel Security, Baseline tab with the Upload CSV button beside a portal name
Security, Baseline, then Upload CSV beside the portal.

Export all users, not Export view. A filtered view can miss deactivated or pending users and the baseline would be incomplete.

ControlWhat it does
Upload CSVButtonAdministrators only. Choose a HubSpot user export. The file is parsed in your browser, validated and imported as the active baseline for the selected portal. Up to 10,000 rows.
From baselineButtonOpens Create templates from this baseline, which proposes role templates from the roles found in the baseline.

Scan status

Scheduled job status and the contact access scan status live under Admin, System, Operations, which is available to FlowSentinel staff. Alerts on this tab are the output of those scans.