Email & CRM · Integration

Share HubSpot access without sharing a password

Last updated: August 2026

To give an agency access to HubSpot, use HubSpot user seats and permission sets — the agency is added as a user with granular permissions. No password is shared, the client keeps ownership of HubSpot portals, and access can be removed anytime.
Full step-by-step guide

The official way to grant HubSpot access

HubSpot user seats and permission sets — the agency is added as a user with granular permissions. You'll find it under Settings → Users & Teams → Create user. The client keeps ownership of HubSpot portals; the agency is granted only what you assign.

The mistake almost everyone makes: Sharing a seat throws away HubSpot's granular permissions and blurs who changed what in the CRM.

What you'll need first

Access levels explained

Grant the least access the work needs. Here's what each level on HubSpot can do:

Access level / roleWhat it can do
Super AdminFull access to everything including users. Keep this.
Permission set (custom)A saved bundle of granular permissions — the clean way to grant agencies exactly what they need.
Tool-level permissionsMarketing, Content, Reports, CRM etc., each toggled per user.
Sales/Service seatsAssign only if the agency uses those hubs.

How long it takes

A few minutes to create the user and assign permissions; the agency accepts the invite.

Why this is safer than sharing a password

The agency gets its own seat with exactly the permissions you assign — no shared login. Granular permission sets keep the CRM auditable; remove or deactivate the user anytime.

Or do it in one link

Every step above is why agencies move to a single link. HandItSafe requests exactly the HubSpot access you need — the client approves it through HubSpot's own process in about three minutes, no password shared, and keeps a panel to see and remove access anytime. That visibility is why clients approve faster, and it makes offboarding a one-tap job later.

Read the full step-by-step guide to giving HubSpot access

FAQ

HubSpot access — your questions answered

Do I share my HubSpot login?

No. The agency gets their own seat with exactly the permissions you assign.

What permissions does an agency need?

Match the tools they'll use — Marketing, Content, Reports — and leave the rest off.

How do I remove HubSpot access?

Users & Teams → remove the user. HandItSafe adds one-tap client removal.

How do I give an agency just marketing access?

Create a permission set with Marketing and Reports enabled and the rest off, then assign it to the agency users.

Do agency users cost a seat?

Depends on your HubSpot plan and which hubs they need. Marketing/Content access is usually included; paid Sales/Service seats are assigned only if needed.

Keep reading

Related guides

Skip the whole thing — send one link.

HandItSafe requests exactly this access in one link. No passwords. Your client keeps a panel to remove it anytime.