You have been handed a HubSpot portal with no data dictionary, no owner and no map of what runs. Do not touch a workflow yet. The fastest safe path is a read-only inventory in a fixed order: confirm Super Admin access, list every user and their permissions, export the property catalog, read the lifecycle and pipeline logic, then enumerate active workflows and connected apps before you change anything. This guide is that inventory, step by step, with the exact screens and exports to pull.
Key takeaways
- The short answer: audit in read-only order (access, users, properties, lifecycle, pipelines, workflows, integrations) and produce a written inventory before making a single change.
- You need Super Admin to see automation, permissions and data-model settings; a Marketing or Sales seat will hide the exact things an audit must surface, per HubSpot's permissions guide.
- A portal caps at 500 workflows and 1,000 custom properties per object on paid tiers, so a portal near either ceiling is already a governance problem you inherited.
- The default Lifecycle stage property only moves forward through HubSpot tools, so stage regressions and stalls are almost always caused by workflows or integrations clearing the value, not by the property itself.
- Duplicates are the most common cause of reporting that does not tie out; HubSpot deduplicates contacts by Email and companies by Company domain name, so anything created outside those keys can double count.
- Finish with a one-page inventory and a ranked risk list. The deliverable of a first-week audit is documentation and a plan, not fixes.
What you need before you start
- Super Admin access. Ask the account owner to promote your seat. Only Super Admin exposes automation, user permissions and data-model limits together, as described in HubSpot's user permissions guide.
- The subscription tier of every Hub. Marketing, Sales, Service, Content and Operations Hub each have their own tier, and the tier decides which limits and tools apply.
- Export and reporting rights, so you can pull property and contact exports for offline review.
- A blank spreadsheet for the inventory: one tab each for users, properties, lifecycle, pipelines, workflows and integrations.
- A rule for yourself: read-only for the whole first pass. You are documenting, not repairing.
Run the audit in this exact order
- Confirm your access and inventory every user. Go to
Settings > Users & Teams. Export the user list and record each user's role, permission set, team, last login and Super Admin flag. HubSpot's permission model groups access into CRM, Marketing, Sales, Revenue, Service, Data Management, Automation, Reporting and Account, so note who can edit workflows and who can delete records. Flag every Super Admin and every dormant seat. - Map teams against the real org chart. In the same screen, open
Teams. Confirm team membership matches who actually does the work. Orphaned teams and users in no team are a sign the portal drifted from its setup. - Export the full property catalog per object. Go to
Settings > Properties, select each object (Contacts, Companies, Deals, Tickets, plus any custom objects) and export. Sort by creation date and by group. You are hunting for two things: near-duplicate properties that capture the same fact under different names, and properties with no fill. HubSpot's paid tiers allow up to 1,000 custom properties per object, and inherited portals routinely carry hundreds of dead ones. - Read the lifecycle stage configuration before you trust any funnel number. Open
Settings > Objects > Contacts > Lifecycle Stage. Record the default stage for new records, whether association-based stage sync is on, and the default stage set for each connected app. Remember that the default Lifecycle stage property can only move forward through HubSpot tools, so any backward movement you see is a workflow or import clearing the value. If the funnel looks wrong, this is usually why; the mechanics are covered in the guide to HubSpot lifecycle stages moving backwards. - Inventory every pipeline and its stages. Go to
Settings > Objects > Deals > Pipelines(and Tickets). For each pipeline, list the stages, their probabilities and any stage-based automation. Multiple half-used pipelines with overlapping stage names are a classic inherited mess that breaks close-rate reporting. - Enumerate active and inactive workflows. Open
Automation > Workflows. Sort by status and by last-modified date. Export the list and record for each: object type, enrollment trigger, whether re-enrollment is on, and whether it edits lifecycle stage, owner or any high-traffic property. A portal is capped at 500 workflows including inactive ones, so a portal near that number needs consolidation before anything else. Two workflows that write the same property are your first collision suspects. - List connected apps and integrations. Go to
Settings > Integrations > Connected Apps. For each app, note what it writes into HubSpot, which properties it owns, and which user authorized it. An integration that sets lifecycle stage or creates contacts is a data source you do not yet control. - Measure data quality. If the portal has Operations Hub Professional or Enterprise, open
Data Management > Data Quality. HubSpot's data quality command center surfaces duplicates, formatting issues and unused properties in one view. On any tier, run a duplicates check: HubSpot deduplicates contacts by the Email property and companies by Company domain name, so records created without those keys will double count. - Write the inventory and rank the risks. Fill each spreadsheet tab, then produce a one-page summary: total users and Super Admins, property count and duplicate count per object, active workflow count, pipeline count, and connected apps. Rank issues by blast radius. Only after this is written do you propose changes.
What to audit, where to look, and the red flag
| Audit area | Where to look | Red flag to record | Priority |
|---|---|---|---|
| Access and users | Settings > Users & Teams | Many Super Admins, dormant seats, no team structure | High |
| Properties | Settings > Properties (export per object) | Duplicate fields, properties with near-zero fill | High |
| Lifecycle logic | Settings > Objects > Contacts > Lifecycle Stage | Association sync and app defaults both fighting the funnel | Critical |
| Pipelines | Settings > Objects > Deals / Tickets > Pipelines | Overlapping stages, unused pipelines | Medium |
| Workflows | Automation > Workflows | Near the 500 cap, two workflows writing one property | Critical |
| Integrations | Settings > Integrations > Connected Apps | App silently owning lifecycle stage or owner | High |
| Data quality | Data Management > Data Quality | High duplicate rate, malformed formatting | High |
Supporting depth
Why properties come first, before workflows
Workflows, reports and integrations all read and write properties, so the property catalog is the map everything else references. If two properties hold the same fact, every downstream report inherits the split. Sort your export by fill rate: a property with data on a handful of records is either abandoned or fed by one broken source. Note which properties are calculated, which are HubSpot defaults, and which are owned by an integration, because those three categories have different rules for who is allowed to change them.
Reading lifecycle stage as a system, not a field
Lifecycle stage is set from more places than any other property: manual edits, forms, imports, workflows, association sync and connected apps. Because the default property only advances through HubSpot tools, the failure you will see most is a stage that never regresses when it should, or one that jumps because an import cleared it first. Document every writer of the stage before you touch any of them. Attribution and reporting mismatches often trace back to this same tangle, which is the pattern behind HubSpot and Google Ads attribution disagreements.
Workflow collisions
Two workflows that write the same property with different logic will produce records whose value flips depending on which ran last. Build a small matrix: rows are high-traffic properties (lifecycle stage, contact owner, deal stage), columns are workflows, and mark every cell where a workflow writes that property. Any property with two or more marks is a collision to investigate. Re-enrollment settings make this worse, because a record can re-enter and overwrite a value set moments earlier.
Troubleshooting the audit itself
- You cannot see a settings area. You are not Super Admin, or the Hub that owns it is on a tier your seat cannot reach. Confirm both before assuming the feature is off.
- The workflow list looks short but automation clearly runs. Check for form follow-up, sequences and integration-driven updates, which are not workflows but still write data.
- Property fill rates look wrong. Exports reflect the current filter and view; export the full object with no active filter, or the numbers will undercount.
- Duplicate counts differ between tools. The data quality command center uses a matching model, while the merge tool matches on the unique keys; treat the command center as the wider net and confirm each candidate before merging.
How to verify the audit is complete and correct
You are done when the numbers reconcile and the inventory is written, not when the screens look familiar. Concrete checks:
- Your user tab total equals the seat count in
Settings > Users & Teams, and every Super Admin is named and justified. - Your property tab per object matches the count HubSpot shows in the property settings header, so nothing was missed by a filter.
- Every writer of Lifecycle stage is listed: default setting, each connected app default, association sync state, and each workflow that edits it.
- Your active workflow count matches the Automation tool's status filter, and the number sits comfortably below the 500 cap.
- The one-page summary exists and a colleague who has never seen the portal can read it and know who has access, what runs, and what the top three risks are.
If any of those five fail, the audit is not finished. Only once the inventory reconciles should you schedule the first change, and make it reversible.