# HubSpot Superadmin Audit

> Connect your HubSpot portal and get real numbers back: how many contacts have no company, how many open deals are overdue, how many tickets have no owner. Read-only, and the access is not kept.

The interactive tool is at https://c2suite.com/en/resources/hubspot-superadmin-audit.

## How it differs from the other HubSpot assessment

There are two HubSpot assessments on this site, and they are not the same. The other one asks: you answer it in five minutes, and it works whatever portal you have. This one measures: it connects to your portal, counts what is inside and gives you numbers instead of answers. To use it, you need to be a super admin.

## What you need to use it

- **Be a super admin** of the portal, or have the App Marketplace Access permission. HubSpot requires it to install any app.
- **Confirm a warning.** The app is not listed in the HubSpot App Marketplace, and since March 2026 HubSpot asks for an explicit confirmation in that case.
- **The installation screen shows the domain `c2suite.com`**, which is the verified domain of C2Suite's developer account and the same site the tool is on. That is how to check the screen is the right one: if any other domain appears there, it is not this app.
- Nothing else: no software to install, no payment, and no specific HubSpot plan required.

## Which permissions it asks for

Read-only, and only the ones the checks use. They come in two groups because HubSpot treats them differently: required permissions block installation if the portal does not offer them, and optional ones are granted only if they are available in that account.

- Required: `crm.objects.contacts.read`, `crm.objects.companies.read`.
- Optional: `crm.objects.deals.read`, `crm.objects.tickets.read`, `automation`.
- It does not ask for any write permission, or for content.

## What it doesn't measure, and why

This one measures what can be counted from the outside: data and properties, pipeline, tickets, and automation. The questionnaire also asks about adoption and marketing, and both gaps are deliberate.

- **Adoption.** Whether the team works inside the portal or fills it in later cannot be inferred from any count: a tidy portal can be dead, and a messy one can be very much alive.
- **Marketing.** Counting sends, forms and campaigns would require permissions this app deliberately does not request: every extra permission on the installation screen is a reason not to continue.
- **Automation is measured**, but only if the portal has it: workflows require a paid plan, so in a free portal that area does not appear instead of appearing at zero.
- For those two, the questionnaire at https://c2suite.com/en/resources/hubspot-assessment is still the best reading available.

## How it is calculated

1. **Count for a check** = how many records in the group meet the condition being checked, out of how many records are in that group. The group is the universe of the question (**open** deals, not all deals), and that is the difference between a useful number and one that improves on its own as the portal builds up history.
2. **Points for a check** = 0 to 3, depending on which of the four ranges that percentage falls into. The three cutoffs of each check are listed below, with the reason for each.
3. **Area score** = points earned ÷ possible points × 100, where the possible points are 3 × the weight of each of its checks.
4. **Total score** = the average of the areas, weighted by each area's weight. Only areas where at least one check could be read are included.
5. **What could not be read does not score.** An area with no reading is left out of the average instead of counting as zero, and the report says which area it was and for which of three reasons: there are no records of that type, that permission was not granted, or the read failed.
6. **Gap for a check** = (3 − points earned) × its weight. This is what orders the list of findings.
7. **Priority of a finding** = gaps are sorted from largest to smallest and added up as a share of the total. The priority is decided by the cumulative share **before** that finding: below 0.5 it is high, below 0.8 it is medium, and the rest is low.

## Reading the score

These are the same cutoffs as the questionnaire, so the two tools do not give two different readings of the same portal.

### 0–39: The data can't support a decision

The numbers above are not a one-off oversight: they are the normal state of the portal. This is not the place to start automating anything, because any workflow built on top of this multiplies the mess. The first step is to stop incomplete records where they come in; cleaning up what is already inside without fixing the source is work that undoes itself.

### 40–64: It works, with gaps you pay for every month

There is structure and people are using it, but the gaps below are being paid for in manual work and in reports that get debated instead of used. This is the point where cleaning up pays off most: the foundation is there, and what is missing are specific decisions, not a reimplementation.

### 65–84: Solid, with a few specific gaps

The portal is well run. What remains are specific areas, which is why the list below is short: there is nothing to rebuild, just three or four specific things to close, and they can be fixed in bulk.

### 85–100: Well run

Little to fix in what can be counted from the outside. At this level, improvements are no longer about data hygiene but about judgment, and those are not measured with counts: attribution, forecasting and automations that depend on data that lives outside the portal today. If anything in the list below surprises you, start there; if not, your next step is not in HubSpot.

## The 4 areas

- **Data and properties** (weight 3, 4 checks). Whether you can trust what is inside. We count how many records are missing the field that makes them usable: the company a contact belongs to, a company's domain, the email HubSpot uses to deduplicate.

- **Pipeline** (weight 3, 3 checks). Whether the pipeline matches reality. An open deal with a past close date is not a deal. It is a reminder nobody acted on, and while it stays there the forecast is wrong.

- **Tickets** (weight 2, 2 checks). What comes in through support, and whether someone is in charge of answering it.

- **Automation** (weight 2, 1 check). How much of the follow-up happens without anyone having to remember it. Twenty workflows that nobody understands do not make a portal automated; they make it hard to change.

## The 10 checks

Each check has its weight within the area, the three cutoffs that split its percentage into four ranges, and the reason they sit where they do. Read the cutoffs like this: up to the first one is 3 points, up to the second 2, up to the third 1, and above that 0.

### Data and properties

#### Contacts without an associated company
- Measured out of: contacts.
- Weight: 3.
- Cutoffs: 5% / 15% / 30%.
- Why these cutoffs: A contact without a company does not appear in any account-based report, does not inherit its company's owner, and cannot be segmented by industry or size. Some always slip through, such as blog subscribers or personal contacts, so up to 5% is normal noise. From one third upward it is no longer an oversight: nobody is associating them.
- What to do: Associate what you can in bulk by email domain, and make the association a required step in the form or workflow that creates contacts.

#### Contacts without an email
- Measured out of: contacts.
- Weight: 3.
- Cutoffs: 2% / 8% / 20%.
- Why these cutoffs: Email is the key HubSpot uses to deduplicate contacts. Without it, the same person is created again every time someone imports them, and there is no way to reach them through the only channel the portal can use on its own. These are the strictest cutoffs in the catalog because there is no good excuse for this.
- What to do: Find where those records come from (almost always an import or an integration) and fix the source before you clean up what is already inside.

#### Contacts without an owner
- Measured out of: contacts.
- Weight: 2.
- Cutoffs: 20% / 45% / 70%.
- Why these cutoffs: Without an owner, there is nobody to ask about that contact and nobody to notify when they do something. These cutoffs are looser than the rest of this area on purpose: a database normally has a long tail of cold, unassigned contacts, and requiring an owner on all of them would mean someone carrying thousands of records they will never touch.
- What to do: Assign an owner at least to the contacts in an active lifecycle stage, and turn on automatic assignment for everything that comes in from now on.

#### Companies without a domain
- Measured out of: companies.
- Weight: 3.
- Cutoffs: 5% / 15% / 35%.
- Why these cutoffs: The domain is what makes a company unique in HubSpot: HubSpot uses it to deduplicate, to associate contacts automatically and to enrich records. Without a domain, “Acme Industrial” and “Acme Industrial Inc.” live side by side as two companies, and no account-based report adds up.
- What to do: Fill it in where you can infer it from its contacts' email addresses, and merge the duplicates that show up as you do.

### Pipeline

#### Open deals with a past close date
- Measured out of: open deals.
- Weight: 3.
- Cutoffs: 5% / 20% / 40%.
- Why these cutoffs: This is the number that exposes an unmaintained forecast fastest. An open deal with a past date has already missed its commitment and still counts toward the pipeline: while it stays there, the figure presented in the sales meeting includes money that will not come in on the date it says.
- What to do: Close or reforecast every overdue deal before the next cutoff, and keep a saved view with this filter so they do not pile up again.

#### Open deals not updated in 60 days
- Measured out of: open deals.
- Weight: 2.
- Cutoffs: 10% / 30% / 50%.
- Why these cutoffs: Sixty days is longer than any normal sales cycle for mid-sized B2B deals in Mexico: if nobody touched the record in two months, either the deal is dead or the work is happening outside the portal. Both are problems and they are fixed differently, which is why this is shown separately from overdue deals.
- What to do: Go through that list with each sales rep and decide one by one: close it, reforecast it, or record what happened and was never logged.

#### Open deals with no associated contact
- Measured out of: open deals.
- Weight: 2.
- Cutoffs: 2% / 10% / 25%.
- Why these cutoffs: A deal without a contact is a number without a person: nobody can be emailed, it cannot enter a sequence, and if the sales rep leaves, nobody knows who they were talking to. It is one of the cheapest things to fix and one of the most painful when it is missing.
- What to do: Associate the contact you are negotiating with on each one, and make the association a requirement for creating a deal.

### Tickets

#### Open tickets without an owner
- Measured out of: open tickets.
- Weight: 3.
- Cutoffs: 2% / 10% / 25%.
- Why these cutoffs: An open ticket without an owner is a customer request nobody accepted. Unlike an unassigned contact, here someone on the other side is waiting for an answer, which is why the cutoffs are almost as strict as those for contacts without an email.
- What to do: Set up automatic assignment (round robin or by team) in the ticket pipeline, and clear the queue of unowned tickets that has already built up.

#### Open tickets not updated in 60 days
- Measured out of: open tickets.
- Weight: 2.
- Cutoffs: 5% / 15% / 35%.
- Why these cutoffs: Two months without touching an open ticket almost always means it was resolved somewhere else and nobody closed it. While those tickets stay open, no resolution time the portal reports looks like the real one.
- What to do: Close in bulk what has already been resolved, and set up an automatic reminder for tickets that pass a certain age with no activity.

### Automation

#### Workflows turned off
- Measured out of: workflows.
- Weight: 2.
- Cutoffs: 10% / 30% / 50%.
- Why these cutoffs: A workflow that is turned off is not a mistake by itself (a seasonal campaign is turned off when it ends). But a portal where half the workflows are off has no automation left, only old workflows nobody dares to delete because nobody knows what they did. Up to one in ten is normal maintenance; from half upward, what you have is fear of touching anything.
- What to do: Go through the workflows that are turned off one by one and decide for each: delete it, or document why it is still there. What you should not do is leave them for the next person to find, who will not dare to touch them either.

## What happens to the data

- **Only counts leave the portal.** No contact, email or customer name leaves HubSpot: each query asks for a single record and keeps the total.
- **The access token is not stored.** It is used in the same request that asked for it, the report is displayed and the token is discarded. There is no database and there are no accounts.
- **The report cannot be opened again**, which is why it is sent by email: that copy is the one that remains.
- **The email and the resulting report are stored** (the numbers, not the records) in the C2Suite CRM. This is listed in the privacy notice.
- Access is removed from the portal itself, under Settings → Integrations → Connected Apps.

## It doesn't ask. It counts

Each check is a query to your portal that returns a number. “How many contacts have no associated company”, not “Do you associate your contacts with companies?”. The result does not depend on how well you remember or how optimistic you feel on the day you answer.

- It reads counts, never your records: no query brings back contacts, emails or anyone's name.
- Everything is counted with the filters of HubSpot's own API, the same ones you could set up yourself in a saved view.
- A check that cannot be counted with a filter is left out. That is what keeps the report light on your portal.

## From a count to a score

A number on its own does not tell you whether it is good. Each check has three cutoffs that split its percentage into four ranges, from 0 to 3 points, and each cutoff comes with a written reason for where it sits.

- The cutoffs are not all equally strict: contacts without an email is much stricter than contacts without an owner, because one has no good excuse and the other does.
- The percentage is calculated on the group the question belongs to: overdue deals are measured against open deals, not against every deal from the last five years.
- Each check has a weight of 2 or 3 within its area, depending on what it costs to leave it as it is.

## From each area to the total

The score at the top is the average of the areas weighted by their weight, not a simple average. These are the same weights the questionnaire uses, so the two tools do not give you two different rankings of the same portal.

- Each area weighs what it costs to leave it as it is: data and properties weighs 3; pipeline weighs 3; tickets weighs 2; automation weighs 2.
- Weighting keeps a cheap area from offsetting an expensive one just because it has the same number of checks.
- The breakdown is always shown: a portal is rarely bad at everything, and the average hides exactly the area that brought you here.

## What couldn't be read doesn't score

An area that could not be measured is left out of the average instead of counting as zero. A red ring over something nobody looked at is a bad score for nothing, and the report says which areas they were and why.

- If you have no records of that type, there is nothing to fix, and the report says so instead of calling it a failure.
- If you didn't grant that permission, the report says so, and you can connect again and grant it.
- If the read hit your portal's request limit (which you share with your other integrations), the report says so, and you can try again.

## What it doesn't measure, and why

This one measures what can be counted from the outside: data and properties, pipeline, tickets, and automation. The questionnaire also asks about adoption and marketing, and those two are not missing for lack of time.

- Not adoption. Whether the team works inside the portal or fills it in on Fridays cannot be inferred from any count: a tidy portal can be dead, and a messy one can be very much alive.
- Not marketing either, for a different reason: counting sends, forms and campaigns would require permissions this app deliberately does not request. The permissions screen is where most people drop off, and every extra permission is a reason not to continue.
- For those, the questionnaire is still the best reading available, and it is free too.
- And if your portal does not include workflows, you will not see that area at all instead of seeing it at zero: what cannot be measured does not score.

## Frequently asked questions

### How is this different from the other HubSpot assessment?

This one reads your portal; the other one asks you questions. This one connects, counts what is inside and returns real numbers, but it only measures what can be counted from the outside (data and properties, pipeline, tickets, and automation) and you need to be a super admin. The questionnaire also covers adoption and marketing, anyone can answer it in five minutes, and it does not ask for access to anything. They do not compete: if you have the permissions, take both and compare what you think is happening with what is actually happening.

### Which permissions will it ask for, exactly?

Read-only permissions, and only the ones the checks actually use: contacts and companies as required, and deals, tickets and workflows as optional. It does not ask for any write permission, for content, or for anything “just in case”. If you do not grant the optional ones, the report is shorter and tells you what was left out.

### Do you store my access token?

No. It is used in that same request to run the queries, your report is displayed and the token is discarded. There is no database, no accounts and nothing to revoke on our side. One consequence is worth knowing before you start: the report cannot be opened again, which is why we email it to you. That email is your copy.

### Why does HubSpot say the app has not been reviewed?

Because it is not listed in the HubSpot App Marketplace, and since March 2026 HubSpot asks for an explicit confirmation before you install any third-party app that is not listed. It does not mean anything is wrong. It means we have not gone through their review process, which is optional and is what gets an app into their directory.

### How do I know the permissions screen is really yours?

Because HubSpot shows there the domain we have verified with them, and it is c2suite.com: the same site you came from. If you see that domain, you are in the right place. If you see any other domain, do not continue, and let us know.

### Do I need to be an admin?

Yes: a super admin of the portal, or a user with the App Marketplace Access permission. HubSpot requires it to install any app; we do not. If you are not one, the installation screen will not let you finish. In that case the questionnaire is the better option, since it does not ask for access to anything.

### Does it work if I only have the free CRM?

Yes, and it is designed for that. Contacts, companies, deals and tickets exist in a free portal, so those areas are measured the same way. What you will not see is the automation area, because workflows require a paid plan: instead of getting a zero for something that does not exist there, that area simply does not appear, and the report says so.

### How do I remove access afterward?

From your own portal, under Settings → Integrations → Connected Apps, where you disconnect it. You do not need to ask us or wait for anyone. That said, the token was already discarded when your report finished, so disconnecting the app does not delete anything we have: it closes the door for the future.

### What happens to my data?

Only counts leave your portal: how many records meet each condition. No contact, no email and no name of any of your customers leaves HubSpot. What we do keep is your email and the resulting report (the numbers, not the records) in our CRM, which is what lets us write to you about your case instead of sending a generic message. It is listed in the privacy notice.

---

Source: https://c2suite.com/en/resources/hubspot-superadmin-audit

You can cite and summarize this content if you credit C2Suite and link to the source URL.
