Step-by-step guide
Last updated: August 2026
Have these ready — it's what onboarding stalls on:
Grant the minimum the work needs. On HubSpot, the levels are:
| Access level / role | What it can do |
|---|---|
| Super Admin | Full access to everything including users. Keep this. |
| Permission set (custom) | A saved bundle of granular permissions — the clean way to grant agencies exactly what they need. |
| Tool-level permissions | Marketing, Content, Reports, CRM etc., each toggled per user. |
| Sales/Service seats | Assign only if the agency uses those hubs. |
A few minutes to create the user and assign permissions; the agency accepts the invite.
Open Settings → Users & Teams → Create user and grant the access — a few minutes.
Accept and confirm from their side, then start work.
Access is granted when:
The most common problems and how to fix them:
Create a permission set scoped to what the agency does, rather than making them Super Admin.
Their permission set doesn't include it — edit the set or the user's permissions.
The agency gets its own seat with exactly the permissions you assign — no shared login. Granular permission sets keep the CRM auditable; remove or deactivate the user anytime.
Everything above is why agencies switch to a single link. HandItSafe requests exactly this HubSpot access for you — the client approves through HubSpot's official process in about three minutes, no password shared, and keeps a panel to remove it anytime. When the engagement ends, removing access is one tap with a full log.
FAQ
No. The agency gets their own seat with exactly the permissions you assign.
Match the tools they'll use — Marketing, Content, Reports — and leave the rest off.
Users & Teams → remove the user. HandItSafe adds one-tap client removal.
Create a permission set with Marketing and Reports enabled and the rest off, then assign it to the agency users.
Depends on your HubSpot plan and which hubs they need. Marketing/Content access is usually included; paid Sales/Service seats are assigned only if needed.
Keep reading
HandItSafe requests exactly this access in one link. No passwords. Your client keeps a panel to remove it anytime.