Email & CRM · Integration
Last updated: August 2026
HubSpot user seats and permission sets — the agency is added as a user with granular permissions. You'll find it under Settings → Users & Teams → Create user. The client keeps ownership of HubSpot portals; the agency is granted only what you assign.
Grant the least access the work needs. Here's what each level on HubSpot can do:
| Access level / role | What it can do |
|---|---|
| Super Admin | Full access to everything including users. Keep this. |
| Permission set (custom) | A saved bundle of granular permissions — the clean way to grant agencies exactly what they need. |
| Tool-level permissions | Marketing, Content, Reports, CRM etc., each toggled per user. |
| Sales/Service seats | Assign only if the agency uses those hubs. |
A few minutes to create the user and assign permissions; the agency accepts the invite.
The agency gets its own seat with exactly the permissions you assign — no shared login. Granular permission sets keep the CRM auditable; remove or deactivate the user anytime.
Every step above is why agencies move to a single link. HandItSafe requests exactly the HubSpot access you need — the client approves it through HubSpot's own process in about three minutes, no password shared, and keeps a panel to see and remove access anytime. That visibility is why clients approve faster, and it makes offboarding a one-tap job later.
FAQ
No. The agency gets their own seat with exactly the permissions you assign.
Match the tools they'll use — Marketing, Content, Reports — and leave the rest off.
Users & Teams → remove the user. HandItSafe adds one-tap client removal.
Create a permission set with Marketing and Reports enabled and the rest off, then assign it to the agency users.
Depends on your HubSpot plan and which hubs they need. Marketing/Content access is usually included; paid Sales/Service seats are assigned only if needed.
HandItSafe requests exactly this access in one link. No passwords. Your client keeps a panel to remove it anytime.