Step-by-step guide

How to give agency access to HubSpot

Last updated: August 2026

How to give agency access to HubSpot: use HubSpot user seats and permission sets — the agency is added as a user with granular permissions. Open Settings → Users & Teams → Create user, add the agency, choose the access level, and confirm. You never share a password and can remove access anytime.

Before you start

Have these ready — it's what onboarding stalls on:

Step-by-step

  1. In HubSpot, go to Settings → Users & Teams.
  2. Click Create user.
  3. Enter the agency member's email.
  4. Assign a permission set or set permissions granularly.
  5. Send the invite.
Where 90% of onboardings fail: Sharing a seat throws away HubSpot's granular permissions and blurs who changed what in the CRM.

Which access level to grant

Grant the minimum the work needs. On HubSpot, the levels are:

Access level / roleWhat it can do
Super AdminFull access to everything including users. Keep this.
Permission set (custom)A saved bundle of granular permissions — the clean way to grant agencies exactly what they need.
Tool-level permissionsMarketing, Content, Reports, CRM etc., each toggled per user.
Sales/Service seatsAssign only if the agency uses those hubs.

How long it takes, and who does what

A few minutes to create the user and assign permissions; the agency accepts the invite.

What you (the client) do

Open Settings → Users & Teams → Create user and grant the access — a few minutes.

What the agency does

Accept and confirm from their side, then start work.

How to check it worked

Access is granted when:

If it doesn't work

The most common problems and how to fix them:

Over-granting Super Admin

Create a permission set scoped to what the agency does, rather than making them Super Admin.

Agency can't access a tool

Their permission set doesn't include it — edit the set or the user's permissions.

Why you don't share a password

The agency gets its own seat with exactly the permissions you assign — no shared login. Granular permission sets keep the CRM auditable; remove or deactivate the user anytime.

The faster way: one link

Everything above is why agencies switch to a single link. HandItSafe requests exactly this HubSpot access for you — the client approves through HubSpot's official process in about three minutes, no password shared, and keeps a panel to remove it anytime. When the engagement ends, removing access is one tap with a full log.

FAQ

Giving HubSpot access — questions

Do I share my HubSpot login?

No. The agency gets their own seat with exactly the permissions you assign.

What permissions does an agency need?

Match the tools they'll use — Marketing, Content, Reports — and leave the rest off.

How do I remove HubSpot access?

Users & Teams → remove the user. HandItSafe adds one-tap client removal.

How do I give an agency just marketing access?

Create a permission set with Marketing and Reports enabled and the rest off, then assign it to the agency users.

Do agency users cost a seat?

Depends on your HubSpot plan and which hubs they need. Marketing/Content access is usually included; paid Sales/Service seats are assigned only if needed.

Keep reading

Related guides

Skip the whole thing — send one link.

HandItSafe requests exactly this access in one link. No passwords. Your client keeps a panel to remove it anytime.