HubSpot Audit: Charter, Hub-by-Hub Tests, Evidence and the Findings Register
HubSpot audits test each hub against the job it was bought to do, with test IDs, pass thresholds, evidence and a findings register that ranks every fix.
Paul Maxwell, PhD
AUTHOR
GET WEEKLY REVOPS INSIGHTS
No spam. Unsubscribe anytime.
A company buys HubSpot to fix a forecast, a lead handoff or a renewal process, and two years later the forecast is still assembled in a spreadsheet. The HubSpot audit it then commissions returns a list of unused properties, duplicate contacts and workflows with errors. Each item is real, and none explains the spreadsheet: a configuration check asks whether a setting exists, while the business needs to know whether the portal does the job it was bought to do.
This article sets out an audit method that tests each hub against that job. It starts with the finding itself, then the three entry modes and the context ladder, which decide what the portal is scored against and which tests can run. It then gives the kinds of audit, the test catalogue hub by hub, and the findings register from which every recommendation is generated. A sample portal is audited end to end, and the article closes with symptoms, the procedure and timeline, continuous re-testing in RevAudit, costs and returns, and limits.
Disclosure. RevAudit is a product of Paul Maxwell, the founder of RevOps HQ. It is recommended below for re-running the measurable tests after an audit, and the recommendation should be read with that ownership in view.
A charter is the signed statement of what the revenue system must achieve: its goals, the measure that shows each goal is met, the owner of each measure, and the definitions behind the measures; the contents of a RevOps charter are set out separately. A test is a measurement with an identifier, a named place in HubSpot where it is read, and a pass threshold. A finding is a result that misses its threshold, recorded with its evidence and the charter goal it affects, and the findings register is the table of findings that generates every recommendation.
HubSpot Health Checks and Charter Tests
A HubSpot health check reads settings and counts objects: whether deal stages require properties, whether SLA goals exist, whether forms set a lifecycle stage. A portal built by a competent implementer passes those configuration tests by construction, since the implementer created the settings being checked. A charter test reads the records the settings were meant to produce and compares them with a goal somebody signed, and the two kinds of test can disagree completely.
The sample portal audited below shows the pattern in three hubs. Every deal stage after the first requires a property, both customer-facing ticket pipelines have SLA goals, and all 23 active forms set a lifecycle stage, so the three tests that check a setting exists all pass. The tests that read the records behind those settings fail. A third of open deals, 33.2%, have sat in their stage for more than twice its median; the SLA clock runs at all hours while the support contract counts business hours; and 21.9% of the year's new customers never entered the Opportunity stage.
The first gap has a documented mechanism. Conditional stage properties apply when a user manually creates a record in a stage or moves one into it, so a required property binds the board and not a deal moved by a workflow, an import or an integration.
An audit therefore needs a statement of the job before it can grade what matters. Hygiene thresholds hold without one, but whether a failure matters, and when it is fixed, depends on the charter goal it blocks. A duplicate rate of 2.2% is a warn in any portal; it is urgent only where a charter goal depends on counting each contact once.
Entry Modes: Charter-Led, Goal-Led and Technical Baseline
A charter-led audit scores the portal against a signed charter. Each goal names a measure and each measure names the records it is computed from, so every goal traces to the tests that would show it failing. A goal of forecasting the quarter within 10% by week four, for instance, draws on stage ageing, close-date movement, missing amounts and deal ownership. This mode gives the sharpest findings, because the business has already said what matters.
A goal-led audit serves a portal with no charter. A 60-minute intake with the executive sponsor and the heads of the functions using the portal produces a provisional charter: three to five goals, each with a measure, an owner and a definition. The provisional charter is the audit's first deliverable and is signed before measurement starts, since a finding mapped to a goal nobody agreed will be argued with rather than fixed.
A technical baseline runs the hygiene tests that hold whatever the goals are: sync errors, workflow errors, duplicates, records owned by deactivated users, API headroom and the Super Admin count. It suits the period before a migration, a renewal or an acquisition, when the question concerns the state of the system rather than its fitness for a strategy. Its limit follows from the finding above: it can describe a clean portal that does not do its job, and it can rank findings only by risk and effort.
All three modes share one catalogue and one register. Only the register's charter-goal column changes, filled from the signed charter, from the provisional one, or left empty with the consequence stated in technical terms.
The Context Ladder
The tests an audit can run depend on what the audit is given. Each input below unlocks tests that the inputs above it cannot reach, and the scope statement lists which inputs were supplied, so that a reader can tell a test that passed from a test that was never possible.
| Input | What it unlocks | Tests that need it |
|---|---|---|
| InputA user with view permissions on every object and on account settings | What it unlocksConfiguration and record-level tests in each licensed hub | Tests that need itCRM, MKT, SAL, SVC, REV, CMS and RPT tests |
| InputA Super Admin seat, used read-only by written agreement | What it unlocksThe audit log and private apps, both visible only to Super Admins | Tests that need itACC-03, ACC-04 |
| InputIntegration sync logs | What it unlocksFailing records by app and reason, and the last sync of each app | Tests that need itINT-01, INT-03 |
| InputWorkflow error history | What it unlocksAction logs for 90 days and enrolment history for six months | Tests that need itWF-01, WF-02, WF-04 |
| InputThe audit log | What it unlocksWho changed settings, permissions and security, within its retention window | Tests that need itACC-04, and the history behind any configuration finding |
| InputA finance export for reconciliation | What it unlocksReceipts and ageing from the ledger, to compare with HubSpot | Tests that need itREV-02, REV-03 |
| InputThe sales compensation plan | What it unlocksWhich deal properties carry pay, and therefore carry pressure | Tests that need itWeighting of SAL-03, SAL-04 and ACC-02 |
| InputRole interviews | What it unlocksWork done outside HubSpot, and the reasons behind warn results | Tests that need itThe consequence column of every finding |
Two inputs carry conditions. The centralised audit log and private apps are available only to Super Admins, so reading them needs a Super Admin seat used read-only, granted in writing and removed at the review session. The evidence also expires: workflow action logs are stored for 90 days, enrolment history covers six months, and the audit log's standard views cover 30 days, so all three are captured on the first day.
The compensation plan changes how deal results are read. Where pay depends on bookings in a period, a close date pushed into the next period carries an incentive, and the audit weights the sales tests accordingly; properties holding compensation data are candidates for HubSpot field-level permissions. Role interviews are the only rung that reaches outside the portal, and they record the spreadsheet forecast or the hand reconciliation that the data can show only indirectly.
Kinds of HubSpot Portal Audit
A full portal audit runs the whole catalogue against every licensed hub. Each other kind draws a subset of the catalogue for a narrower question, and it is the better purchase when the question is narrow.
| Kind of audit | Question it answers | Catalogue areas |
|---|---|---|
| Kind of auditFull portal | Question it answersWhether each licensed hub does the job in the charter | Catalogue areasEvery area |
| Kind of auditData quality | Question it answersWhether records are complete, unique, owned and current | Catalogue areasCRM, RPT-01 |
| Kind of auditIntegrations | Question it answersWhether connected systems sync, and which system owns each field | Catalogue areasINT, REV-03 |
| Kind of auditAutomation | Question it answersWhether workflows run without errors, conflict or dormancy | Catalogue areasWF |
| Kind of auditReporting accuracy | Question it answersWhether headline reports include the records they claim to | Catalogue areasRPT, MKT-04 |
| Kind of auditAdoption and seat use | Question it answersWhether paid seats are used and records are maintained by role | Catalogue areasSAL-05, SVC-05, REV-05, interviews |
| Kind of auditPermissions and security | Question it answersWho can change what, and which apps can write to which objects | Catalogue areasACC |
| Kind of auditPre-renewal tier fit | Question it answersWhether the features and seats paid for are in use before the renewal date | Catalogue areasSeat tests, MKT-01, tier-gated features |
| Kind of auditPre-migration | Question it answersWhat to move, rebuild or retire before records leave the portal | Catalogue areasCRM-01, WF-02, INT inventory |
| Kind of auditPost-implementation acceptance | Question it answersWhether the build meets its specification and produces the records it was meant to | Catalogue areasConfiguration tests, then record tests 30 days later |
| Kind of auditAI readiness | Question it answersWhether an assistant or agent would read accurate data and hold only the access it needs | Catalogue areasCRM-02, INT-02, WF-04, ACC-03 |
Post-implementation acceptance runs the configuration tests at handover and the record tests 30 days later, once real records have passed through the settings; acceptance on the first pass alone accepts exactly the gap described above. An AI readiness audit weights duplicates, competing writers and app scopes above the other tests, because an agent acts on whatever the records say.
The HubSpot Audit Checklist: Test Catalogue by Hub
Every test below carries an identifier, the measure, the place in HubSpot where it is read, a pass threshold and the evidence kept. The thresholds are the firm's own standards, set to separate a portal that needs attention from one that does not; they are not industry benchmarks, and no benchmark is cited for any of them.
A ceiling threshold, such as 2% or fewer, passes at or under the ceiling, warns up to twice the ceiling, and fails beyond it. A floor threshold, such as 95% or more, warns when the shortfall is no larger than the gap the floor allows, so 90% warns against a 95% floor and 89% fails. A zero threshold warns on one to five items, which can be listed and fixed by hand, and fails on six or more. A binary test, such as whether a setting matches a contract, passes or fails.
Smart CRM and Data
The property editor shows, under Monitor, where each property is used and its fill rate, and HubSpot's data quality tools chart total properties against issues over a date range; the tooling above them is covered in HubSpot Data Hub. Duplicate management covers contacts and companies only, on Professional and Enterprise, and lists up to 10,000 pairs, rising to 100,000 with Data Hub Enterprise, so a full queue reports a floor rather than a count. Merge rules belong to HubSpot duplicate management.
HubSpot's tools move the default lifecycle stage forward only, and an earlier stage can be set only after the value is cleared, so a backward move in a record's history is a deliberate act. A skipped stage is quieter. With Set lifecycle stage when a deal is won switched on, a deal imported straight into a won stage can move its contacts to Customer with no Date entered Opportunity value written, and the funnel then counts a conversion that never passed through that stage. Lifecycle design is covered in HubSpot lead status vs lifecycle stage.
| Test ID | What it measures | Where it is read in HubSpot | Pass threshold (firm's standard) | Evidence captured |
|---|---|---|---|---|
| Test IDCRM-01 | What it measuresCustom properties populated on fewer than 5% of records, as a share of all custom properties | Where it is read in HubSpotProperty editor, Monitor, usage and fill rate | Pass threshold (firm's standard)15% or fewer | Evidence capturedProperty export with fill rate and usage |
| Test IDCRM-02 | What it measuresDuplicate pairs as a share of records, contacts and companies measured separately | Where it is read in HubSpotContacts or Companies, Actions, Manage duplicates | Pass threshold (firm's standard)2% or fewer | Evidence capturedPair count, queue capture, ten sampled pairs |
| Test IDCRM-03 | What it measuresDeals created in the last 12 months with no associated company | Where it is read in HubSpotDeals index filtered on associated company is unknown | Pass threshold (firm's standard)2% or fewer | Evidence capturedSaved view and record list |
| Test IDCRM-04 | What it measuresCustomers created in 12 months with no Date entered Opportunity value, plus stages cleared and set earlier | Where it is read in HubSpotLifecycle stage date properties and property history | Pass threshold (firm's standard)5% or fewer | Evidence capturedReport on Date entered values, sampled histories |
| Test IDCRM-05 | What it measuresOpen deals and open tickets with no owner | Where it is read in HubSpotRecord indexes filtered on owner is unknown | Pass threshold (firm's standard)Zero | Evidence capturedSaved views |
| Test IDCRM-06 | What it measuresCustom objects with no record created in 90 days | Where it is read in HubSpotData Management, Data Model, custom objects on Enterprise | Pass threshold (firm's standard)Zero | Evidence capturedObject list with record counts and last created date |
Integrations
For each Data Sync app, the CRM syncs tab under Settings, Integrations, Connected Apps shows records failing to sync in a Failing column, with the reason one click further in; the Salesforce connector has its own sync errors view. INT-01 groups failures by reason, since one mapping fault can fail thousands of records and is corrected once.
Property history records each value with its date and source, and HubSpot's change sources define the source labels. Where an accounting sync and a workflow both write a deal's amount, the record holds whichever wrote last, and a report run on Tuesday disagrees with Monday's although nobody edited a deal.
Privately distributed apps on Professional are limited to 190 requests per 10 seconds and 625,000 a day across the account, against 1,000,000 a day on Enterprise and 250,000 on Free and Starter, with usage shown under Development, Monitoring, API call usage. A private app's Logs tab keeps 30 days of calls with response codes, so a 429 rate-limit refusal is visible there before it surfaces as missing data.
| Test ID | What it measures | Where it is read in HubSpot | Pass threshold (firm's standard) | Evidence captured |
|---|---|---|---|---|
| Test IDINT-01 | What it measuresRecords failing to sync as a share of records synced, per app | Where it is read in HubSpotConnected Apps, app, CRM syncs, Failing column | Pass threshold (firm's standard)0.5% or fewer | Evidence capturedFailing-record export grouped by reason |
| Test IDINT-02 | What it measuresProperties written by two or more systems in 30 days with no written precedence rule | Where it is read in HubSpotProperty history source, and the Data Sync field mappings | Pass threshold (firm's standard)Zero | Evidence capturedProperty list with each writing source |
| Test IDINT-03 | What it measuresInstalled apps with no successful sync inside their expected interval | Where it is read in HubSpotConnected Apps list and each app's CRM syncs tab | Pass threshold (firm's standard)Zero | Evidence capturedApp list with last sync date |
| Test IDINT-04 | What it measuresPeak daily API calls as a share of the daily limit, and 429 responses in private app logs | Where it is read in HubSpotDevelopment, Monitoring, API call usage, against the published limits | Pass threshold (firm's standard)Peak day at 60% or less; zero 429 responses | Evidence capturedUsage chart and log export |
Workflows and Automation
Each workflow's Action logs tab filters to Errors. The logs are stored for 90 days, and beyond 100,000 logged successful executions in a day the success and information logs stop while error logs continue. Across the account, Review automation issues collects automations with issues in a Needs review tab, where each is marked fixed, ignored or deferred; WF-01 counts an issue ignored with no recorded reason as open.
Dormancy is read from enrolment history, which reaches back six months. An active workflow with no enrolment in 90 days guards an event that no longer happens or waits on a property nothing writes, and either can fire unexpectedly on a bulk import. Removing a user does not delete the workflows they created, so automation outlives the person who could explain it. Two workflows that set one property produce a value that depends on which ran last, and the property editor's usage view finds every writer in one pass.
| Test ID | What it measures | Where it is read in HubSpot | Pass threshold (firm's standard) | Evidence captured |
|---|---|---|---|---|
| Test IDWF-01 | What it measuresWorkflow actions ending in an error as a share of actions executed in 30 days, by object | Where it is read in HubSpotAction logs filtered to Errors; Review automation issues | Pass threshold (firm's standard)1% or fewer | Evidence capturedError export by workflow and error type |
| Test IDWF-02 | What it measuresActive workflows with no enrolment in 90 days | Where it is read in HubSpotEnrolment history | Pass threshold (firm's standard)10% or fewer of active workflows | Evidence capturedWorkflow list with last enrolment date |
| Test IDWF-03 | What it measuresActive workflows created by users now deactivated or removed | Where it is read in HubSpotWorkflows filtered by creator, against Users and Teams | Pass threshold (firm's standard)Zero | Evidence capturedWorkflow list with creator status |
| Test IDWF-04 | What it measuresProperties set by two or more active workflows with no written precedence rule | Where it is read in HubSpotProperty editor usage view and property history source | Pass threshold (firm's standard)Zero | Evidence capturedProperty-to-workflow map |
Marketing Hub
Only marketing contacts count toward the Marketing Hub contact tier, and a contact set as non-marketing stops counting on the next update date. The Last marketing email send date property records the most recent marketing email delivered, and on Professional and Enterprise a workflow can set contacts as non-marketing once the list is agreed. MKT-01 is therefore a test with a price attached.
A form can set the lifecycle stage of contacts who submit it, and will not move one backwards. MKT-02 checks every active form against the charter's definitions: a newsletter form that sets marketing qualified lead, where the charter defines that stage by a demo request, inflates the stage the marketing goal is measured on. MKT-04 uses the coverage arithmetic from HubSpot attribution reporting: closed-won revenue the attribution path can see, divided by closed-won revenue for the period.
| Test ID | What it measures | Where it is read in HubSpot | Pass threshold (firm's standard) | Evidence captured |
|---|---|---|---|---|
| Test IDMKT-01 | What it measuresMarketing contacts sent no marketing email in 180 days, as a share of marketing contacts | Where it is read in HubSpotContacts filtered on marketing contact status and Last marketing email send date | Pass threshold (firm's standard)15% or fewer | Evidence capturedCount, saved view, current contact tier |
| Test IDMKT-02 | What it measuresActive forms whose lifecycle stage setting matches the charter definition | Where it is read in HubSpotForm settings, Set lifecycle stage to | Pass threshold (firm's standard)Every active form (binary) | Evidence capturedForm list with the stage each sets |
| Test IDMKT-03 | What it measuresSegments unused in any email, workflow, report or ad audience and not updated in 180 days | Where it is read in HubSpotSegments index, active and static lists | Pass threshold (firm's standard)25% or fewer | Evidence capturedSegment list with usage and last update |
| Test IDMKT-04 | What it measuresClosed-won revenue on deals whose contacts carry tracked interactions, as a share of closed-won revenue | Where it is read in HubSpotDeal report against the attribution report for the same period | Pass threshold (firm's standard)80% or more | Evidence capturedBoth totals and the division |
Sales Hub
Pipeline rules on Professional and Enterprise can restrict skipping stages and moving records backwards. SAL-01 is the configuration test, asking whether each stage after the first requires at least one property tied to its exit criterion. The record tests that follow ask whether deals behave as that configuration intends.
Stage calculated properties record when each deal entered and exited each stage and its time in the current stage. SAL-02 flags open deals whose time in stage exceeds twice the median for that stage across deals closed in the last year, and SAL-03 reads close-date changes from a property history export. Where the default deal amount is manual entry, adding line items leaves the amount unchanged, and changing the setting does not update existing deals. The Seats tab under Users and Teams shows each user's seat and last active date, which is where SAL-05 is read.
| Test ID | What it measures | Where it is read in HubSpot | Pass threshold (firm's standard) | Evidence captured |
|---|---|---|---|---|
| Test IDSAL-01 | What it measuresStages after the first that require at least one property tied to an exit criterion | Where it is read in HubSpotDeal pipeline settings, conditional stage properties and pipeline rules | Pass threshold (firm's standard)Every such stage (binary) | Evidence capturedStage-by-stage settings capture |
| Test IDSAL-02 | What it measuresOpen deals whose time in current stage exceeds twice that stage's median | Where it is read in HubSpotStage calculated properties | Pass threshold (firm's standard)15% or fewer of open deals | Evidence capturedDeal list with stage time and stage median |
| Test IDSAL-03 | What it measuresOpen deals whose close date has moved later three or more times | Where it is read in HubSpotClose date property history export | Pass threshold (firm's standard)10% or fewer of open deals | Evidence capturedHistory export for flagged deals |
| Test IDSAL-04 | What it measuresOpen deals with no amount | Where it is read in HubSpotDeals filtered on Amount is unknown, with the default deal amount setting recorded | Pass threshold (firm's standard)2% or fewer | Evidence capturedSaved view and setting capture |
| Test IDSAL-05 | What it measuresPaid Sales seats whose holder was last active more than 30 days ago | Where it is read in HubSpotUsers and Teams, Seats | Pass threshold (firm's standard)5% or fewer | Evidence capturedSeat export |
Service Hub
SLA goals require Service Hub Professional or Enterprise and cover time to first reply, time to next reply and time to close. Each goal applies at all times or during a chosen schedule and time zone, and HubSpot writes SLA due-date and status properties to each ticket. SVC-02 asks which clock the contract uses: an SLA running at all hours against a business-hours contract reports breaches the customer never agreed to count.
A customer support survey is triggered by pipeline and ticket status and sent once per ticket, so coverage depends on every customer-facing pipeline having a trigger. A ticket with no associated company is missing from the company's view of its service history, which is the view a salesperson reads before a renewal call.
| Test ID | What it measures | Where it is read in HubSpot | Pass threshold (firm's standard) | Evidence captured |
|---|---|---|---|---|
| Test IDSVC-01 | What it measuresSLA goals configured on every customer-facing ticket pipeline | Where it is read in HubSpotInbox and Help Desk, Help Desk, SLAs | Pass threshold (firm's standard)Every such pipeline (binary) | Evidence capturedSettings capture |
| Test IDSVC-02 | What it measuresThe SLA clock, at all times or a specific schedule, against the contracted clock | Where it is read in HubSpotThe same SLA settings, schedule and time zone | Pass threshold (firm's standard)Matches the contract (binary) | Evidence capturedContract clause beside the settings capture |
| Test IDSVC-03 | What it measuresTickets closed in 90 days with no associated company | Where it is read in HubSpotTickets filtered on associated company is unknown | Pass threshold (firm's standard)5% or fewer | Evidence capturedSaved view |
| Test IDSVC-04 | What it measuresCustomer-facing pipelines with no survey sent on close | Where it is read in HubSpotCustomer feedback, support survey recipients by pipeline and status | Pass threshold (firm's standard)Zero | Evidence capturedSurvey list with trigger pipeline |
| Test IDSVC-05 | What it measuresPaid Service seats whose holder was last active more than 30 days ago | Where it is read in HubSpotUsers and Teams, Seats | Pass threshold (firm's standard)5% or fewer | Evidence capturedSeat export |
Revenue Hub
The ledger stays outside HubSpot: the end-to-end revenue guide keeps finance in step by syncing revenue data with accounting and ERP tools such as QuickBooks, Xero and NetSuite. REV-01 compares each deal's amount with its accepted quote, since a deal carrying one figure and its quote another gives the forecast and the invoice two numbers for one sale. Line items imported or updated through the API leave the deal amount unchanged, so an integration that writes line items can open that gap without any user seeing it happen.
The default invoice properties include Invoice status, with the values Draft, Open, Paid and Voided, together with Balance due, Days overdue and Age category, enough to build an ageing table beside the finance ageing. On a contract record, the renewal date is the contract end date until a renewal is finalised or a renewal quote accepted, so a contract ending within 120 days with no renewal deal is a renewal nobody is working.
| Test ID | What it measures | Where it is read in HubSpot | Pass threshold (firm's standard) | Evidence captured |
|---|---|---|---|---|
| Test IDREV-01 | What it measuresDeals with an accepted quote whose amount differs from the quote total by more than 1% | Where it is read in HubSpotDeal report with quote totals, line items on deals | Pass threshold (firm's standard)2% or fewer | Evidence capturedDeal list with both values |
| Test IDREV-02 | What it measuresOpen balance over 60 days overdue in HubSpot against the finance ageing, difference as a share of open balance | Where it is read in HubSpotInvoice properties: Days overdue, Age category, Balance due | Pass threshold (firm's standard)5% or less | Evidence capturedBoth ageing tables |
| Test IDREV-03 | What it measuresPaid invoice total in HubSpot against receipts in the ledger for the same period | Where it is read in HubSpotInvoice report against the finance export | Pass threshold (firm's standard)Difference of 0.5% or less, each difference explained | Evidence capturedReconciliation workbook |
| Test IDREV-04 | What it measuresContracts ending within 120 days that have a renewal deal or renewal quote | Where it is read in HubSpotContract records, renewal date | Pass threshold (firm's standard)95% or more | Evidence capturedContract list with renewal status |
| Test IDREV-05 | What it measuresPaid Revenue seats whose holder was last active more than 30 days ago | Where it is read in HubSpotUsers and Teams, Seats | Pass threshold (firm's standard)5% or fewer | Evidence capturedSeat export |
Content Hub
URL redirects work only for domains hosted in HubSpot, default to a permanent 301, and can be exported, which is where CMS-02 finds a redirect whose destination is itself redirected. Orphan pages need a crawl of the live site set against the page export, since HubSpot's page list records what is published and not what links to it.
| Test ID | What it measures | Where it is read in HubSpot | Pass threshold (firm's standard) | Evidence captured |
|---|---|---|---|---|
| Test IDCMS-01 | What it measuresPublished pages with no internal link and absent from navigation | Where it is read in HubSpotWebsite pages export set against a crawl of the live site | Pass threshold (firm's standard)Zero pages intended to rank | Evidence capturedCrawl export with orphans flagged |
| Test IDCMS-02 | What it measuresRedirects whose destination is itself redirected | Where it is read in HubSpotDomains and URLs, URL redirects export | Pass threshold (firm's standard)Zero chains | Evidence capturedRedirect export with chains flagged |
| Test IDCMS-03 | What it measuresTemplates with no published page using them | Where it is read in HubSpotDesign manager template list against the page export | Pass threshold (firm's standard)20% or fewer | Evidence capturedTemplate list with page counts |
Reporting
A headline report is accurate only over the records its filters let in, and it says nothing about the records it leaves out. RPT-01 rebuilds the population behind each headline report as a plain list and divides the report's total by the population's; a forecast that drops deals with no amount shows coverage below 100% that nobody has read. Building such reports is covered in the HubSpot custom report builder.
RPT-02 looks for one metric computed two ways. When two dashboards compute pipeline, marketing qualified leads or win rate with different filters, two teams bring two true numbers to one meeting, a pattern catalogued among the RevOps antipatterns.
| Test ID | What it measures | Where it is read in HubSpot | Pass threshold (firm's standard) | Evidence captured |
|---|---|---|---|---|
| Test IDRPT-01 | What it measuresCoverage of each headline report: report total over the total of the full population it claims | Where it is read in HubSpotThe headline report against the same population rebuilt as a plain list | Pass threshold (firm's standard)95% or more, or the coverage printed on the report | Evidence capturedBoth totals and the filters of each |
| Test IDRPT-02 | What it measuresHeadline metrics computed by two or more reports with different filters or definitions | Where it is read in HubSpotDashboard inventory, compared report by report | Pass threshold (firm's standard)Zero | Evidence capturedMetric-to-report map |
Permissions and Seats
Super Admins can set the permissions of every other user and reach every tool and setting apart from paid Sales and Service features, so their count measures how many people can change the portal without asking anyone. A deactivated user stays assigned to their records, and a removed user's records show Deactivated/Removed with their email address as owner; either way the deal appears in no current representative's own view, and the forecast rolls it up under someone who has left.
A scope granted to a private app for one purpose stays granted for every other. ACC-03 sets the scopes on each app's Scopes tab against the calls in its 30-day Logs tab, and flags write scopes with no write call behind them. ACC-04 reads the audit log's security activity and asks whether each change matches a request somebody can produce.
| Test ID | What it measures | Where it is read in HubSpot | Pass threshold (firm's standard) | Evidence captured |
|---|---|---|---|---|
| Test IDACC-01 | What it measuresUsers holding Super Admin | Where it is read in HubSpotUsers and Teams filtered by permission, per the permissions guide | Pass threshold (firm's standard)Three or fewer, each named | Evidence capturedUser export |
| Test IDACC-02 | What it measuresOpen deals and open tickets owned by deactivated or removed users | Where it is read in HubSpotOwner filters with deactivated owners shown; user removal behaviour | Pass threshold (firm's standard)Zero | Evidence capturedSaved views |
| Test IDACC-03 | What it measuresPrivate apps holding write scopes unused in 30 days or wider than their documented purpose | Where it is read in HubSpotDevelopment, Legacy apps, app, Scopes and Logs, per private apps | Pass threshold (firm's standard)Zero | Evidence capturedScope list against log export |
| Test IDACC-04 | What it measuresSecurity changes in 30 days with no matching request | Where it is read in HubSpotAccount Management, Audit Logs, Security Activity | Pass threshold (firm's standard)Zero | Evidence capturedAudit log export |
The Findings Register
The findings register is the artifact the audit exists to produce. A test result states a number; a register row states the number, what it threatens, what to do about it and what doing it costs. A recommendation with no row behind it has no evidence, and it is removed before the review session.
| Field | What it holds | Sample row |
|---|---|---|
| FieldTest | What it holdsTest ID and the system or hub it ran on | Sample rowINT-01, QuickBooks Online Data Sync |
| FieldMeasurement | What it holdsThe value, the date read and the method | Sample row212 failing of 6,420 synced records, 3.3%, read from the Failing column |
| FieldThreshold | What it holdsThe pass threshold and its grading rule | Sample row0.5% or fewer, ceiling rule |
| FieldResult | What it holdsPass, warn or fail | Sample rowFail: beyond twice the ceiling |
| FieldEvidence | What it holdsWhat was kept, and where | Sample rowFailing-record export grouped by reason; capture of the CRM syncs tab |
| FieldCharter goal affected | What it holdsThe goal the result threatens, or none | Sample rowG3: invoices and renewals in HubSpot agree with the ledger |
| FieldConsequence | What it holdsWhat happens to the business if the row is left open | Sample rowInvoices on 212 records never reach the ledger, and HubSpot receivables drift from finance |
| FieldRecommendation | What it holdsThe specific change, stated so another practitioner can make it | Sample rowCorrect the two field mappings behind 190 of the 212 failures, then resync the failing records |
| FieldEffort | What it holdsEstimated person-days | Sample row2 |
| FieldBenefit | What it holdsScore on the five-point scale below | Sample row5: removes a fail that blocks a charter goal |
| FieldDependencies | What it holdsRows that must close first, and rows waiting on this one | Sample rowNone first; REV-03 waits on this row |
Benefit is scored on a five-point scale that is the firm's standard. A score of 5 removes a fail that blocks a charter goal; 4 removes a fail or warn that degrades one; 3 cuts a recurring licence or labour cost with no goal at stake; 2 reduces the risk of a future fail; 1 is cosmetic. Effort is the auditor's estimate in person-days, revised at the review session by the people who will do the work.
The register rolls up two ways. The hub scorecard counts pass, warn and fail results by hub and test area. The remediation sequence orders open rows by benefit per person-day, highest first, with one constraint: no row is scheduled before the rows it depends on, since a reconciliation run before its sync is fixed would measure the broken sync again.
A Sample Portal Audit
The portal below is sample data and describes no client. A business-to-business services company runs 61 users on Marketing Hub, Sales Hub and Service Hub Professional, with Revenue Hub for quotes, contracts and invoices; its website runs elsewhere, so Content Hub is not licensed and its tests did not run. The portal holds 48,200 contacts, 31,500 of them marketing contacts, 9,400 companies, 1,180 deals created in the last 12 months, 214 open deals and 2,050 tickets closed in 90 days. QuickBooks Online syncs invoices through Data Sync, a Zoom webinar app is installed, and a private app writes product usage from the application database.
With no charter in place, the audit ran in goal-led mode, and the intake produced four provisional goals, signed before measurement began.
| Goal | Measure | Owner |
|---|---|---|
| GoalG1 Forecast | MeasureQuarter forecast within 10% of the outcome by week four | OwnerHead of sales |
| GoalG2 Source | MeasureMarketing-sourced pipeline reported on one definition agreed by sales and marketing | OwnerHead of marketing |
| GoalG3 Cash | MeasureInvoices and renewals in HubSpot agree with the ledger | OwnerFinance lead |
| GoalG4 Support | MeasureFirst reply within the contracted business hours | OwnerHead of support |
The audit took 46 measurements across five hubs: 15 passed, 13 warned and 18 failed. Tests such as the workflow error rate ran once per hub, since the rate means something different on contact, deal and ticket workflows, and each measurement sits under the hub whose records it reads.
Smart CRM
- Measurements
- 12
- Pass
- 5
- Warn
- 3
- Fail
- 4
- Charter goals at stake
- G2
Marketing Hub
- Measurements
- 8
- Pass
- 2
- Warn
- 3
- Fail
- 3
- Charter goals at stake
- G2
Sales Hub
- Measurements
- 11
- Pass
- 3
- Warn
- 2
- Fail
- 6
- Charter goals at stake
- G1, G3
Service Hub
- Measurements
- 9
- Pass
- 4
- Warn
- 4
- Fail
- 1
- Charter goals at stake
- G4
Revenue Hub
- Measurements
- 6
- Pass
- 1
- Warn
- 1
- Fail
- 4
- Charter goals at stake
- G3, G1
Total
- Measurements
- 46
- Pass
- 15
- Warn
- 13
- Fail
- 18
- Charter goals at stake
Sales Hub carries six of the 18 fails, and five bear on the forecast. Stage ageing flags 71 of 214 open deals (SAL-02, 33.2%), and pushed close dates flag 49 (SAL-03, 22.9%). Two deactivated representatives still own 37 open deals (ACC-02), and 94 of the year's 1,180 deals have no company (CRM-03, 8.0%). The forecast report covers 81% of open pipeline amount, since it drops deals with no close date in the quarter (RPT-01). The sixth fail is licence cost: four of 18 paid Sales seats have been idle for more than 30 days (SAL-05).
The register held 31 open rows, the 13 warns and 18 fails. Ordered by benefit per person-day with dependencies honoured, its first five rows are below, and each ratio can be recomputed from the benefit scale.
| Rank | Recommendation | Test and goal | Benefit, effort and ratio | Depends on |
|---|---|---|---|---|
| Rank1 | RecommendationSet both SLA goals to the contracted business-hours schedule and time zone | Test and goalSVC-02, G4 | Benefit, effort and ratio5 over 0.5 days: 10.0 | Depends onNone |
| Rank2 | RecommendationReassign the 37 open deals and 3 open tickets owned by deactivated users | Test and goalACC-02, G1 | Benefit, effort and ratio4 over 0.5 days: 8.0 | Depends onNone |
| Rank3 | RecommendationSet the 10,400 marketing contacts not emailed in 180 days as non-marketing, once marketing signs off the list | Test and goalMKT-01, no goal | Benefit, effort and ratio3 over 1 day: 3.0 | Depends onNone |
| Rank4 | RecommendationCorrect the two field mappings behind 190 of 212 QuickBooks sync failures, then resync | Test and goalINT-01, G3 | Benefit, effort and ratio5 over 2 days: 2.5 | Depends onNone |
| Rank5 | RecommendationReconcile paid invoices against the ledger export and explain each difference | Test and goalREV-03, G3 | Benefit, effort and ratio5 over 1 day: 5.0 | Depends onINT-01 |
The fifth row shows the dependency rule. Reconciliation scores 5.0 per day and would rank third on ratio alone, but it reads invoices the failing sync has not delivered, so it runs directly after INT-01. The sixth row, the company association repair on CRM-03 at 4 over 2 days, unlocks renewal coverage on REV-04, where only 19 of 31 contracts ending within 120 days have a renewal deal. The forecast discipline work on SAL-02 and SAL-03 scores 5 over 5 days and waits on both ACC-02 and CRM-03, since stage discipline rebuilt on deals owned by people who have left, attached to no company, would have to be done twice.
Why HubSpot Is Not Working: Symptoms and Confirming Tests
A business that says HubSpot is not working reports a symptom, and each symptom has a small set of tests that confirm or exclude its mechanism. Starting from the symptom keeps the audit from handing 46 measurements to a sponsor who asked one question.
| Symptom | Mechanism | Tests that confirm it |
|---|---|---|
| SymptomThe forecast is rebuilt in a spreadsheet | MechanismDeals age in stage, close dates slide, amounts are missing and owners have left | Tests that confirm itSAL-02, SAL-03, SAL-04, ACC-02, RPT-01 |
| SymptomMarketing and sales report different pipeline figures | MechanismOne metric has two definitions, lifecycle stages are skipped, and duplicates split a contact's history | Tests that confirm itRPT-02, CRM-04, CRM-02, MKT-04 |
| SymptomThe Marketing Hub bill rises while email volume does not | MechanismBillable marketing contacts are never emailed | Tests that confirm itMKT-01, MKT-03 |
| SymptomFinance does not trust revenue figures from HubSpot | MechanismSync failures, amounts that disagree with quotes, and no reconciliation | Tests that confirm itINT-01, REV-01, REV-03, REV-02 |
| SymptomValues change on records nobody edited | MechanismTwo systems or two workflows write one property | Tests that confirm itINT-02, WF-04 |
| SymptomSupport reports breaches the customer does not recognise | MechanismThe SLA clock differs from the contracted clock | Tests that confirm itSVC-02, RPT-01 |
| SymptomRenewals arrive as surprises | MechanismContracts near their end have no renewal deal | Tests that confirm itREV-04, CRM-03 |
| SymptomRepresentatives keep their own notes and pipelines | MechanismSeats unused, required properties absent, work done outside the portal | Tests that confirm itSAL-05, SAL-01, interviews |
The table separates two questions that a complaint about HubSpot runs together: whether the platform can do the job, and whether this portal is doing it. Every mechanism listed is a property of the portal's configuration, data or use, and none needs a different platform to fix. Symptoms that survive a clean set of tests raise a question of fit, which an audit can frame and cannot settle.
The Audit Procedure and Timeline
The procedure below is the one the HubSpot audit service follows, and the HubSpot audit brief (PDF) summarises it on one page. The firm's planning range is 1 to 2 weeks for a standard audit of one portal, and longer for portals running several hubs with integrations, where measurement and interviews extend into a third week or beyond.
- Agree the scope in writing: hubs, integrations, the period measured, the entry mode, and the rungs of the context ladder supplied. A test outside scope is recorded as not run, never as passed.
- Provision a user with view permissions on every object and on account settings, adding a read-only Super Admin seat, granted in writing, only where the audit log or private apps are in scope.
- On the first day, capture the evidence that expires: the audit log export, workflow action logs and errors, private app logs, and each Data Sync app's failing-record export.
- Settle what the portal is scored against: map signed goals to tests, or run the 60-minute intake and have the provisional charter signed before step 6, or record that no goal is in scope.
- Interview each role that works in the portal for 45 minutes, recording work done outside HubSpot and the reasons behind patterns the data will show.
- Run the tests hub by hub, recording each measurement with its date, method and evidence, and grade it by the four rules.
- Write a register row for every warn and fail, with goal, consequence, recommendation, effort, benefit and dependencies.
- Roll the register into the hub scorecard and the remediation sequence.
- Hold the review session with the measurements open for inspection, and remove the Super Admin seat at its close.
- Verify: a second person re-runs three measurements from the recorded method alone and reaches the same results, and after remediation the failed tests are re-run against the baseline measurement set to confirm each result moved.
The last step separates an audit from an opinion. A finding a second practitioner cannot reproduce from its recorded method is withdrawn, and a remediation never re-measured has not been shown to work.
Continuous Re-Testing with RevAudit
An audit measures one date, and the portal keeps changing: users are deactivated, integrations added, workflows built for the next campaign. The tests that read records and settings through HubSpot can be re-run on a schedule. The tests that need a finance export, a contract clause or an interview cannot, and they wait for the next audit.
RevAudit is built for the scheduled part. Its site lists automated daily audits, health score tracking, email and Slack alerts, data quality and duplicate detection, configuration and compliance checks, and full audit history with reports. One plan at $99 a month covers unlimited HubSpot portals, with a 14-day free trial that requires no credit card, as read in October 2026. Set against the audit's baseline measurement set, an alert on a regression, such as a representative deactivated with deals still open, arrives within days rather than at the next audit.
A health score summarises configuration and data checks, so the opening finding of this article applies to it: the score can rise while a charter goal stays unmet. The register's charter column turns a score into a priority, and the score is read beside the register rather than in its place. Which catalogue tests RevAudit reproduces exactly should be confirmed against its documentation before a daily result is treated as the audit's measurement.
Costs and Returns of a HubSpot Audit
An audit buys a ranked list of changes with evidence behind each. In the sample portal, the first five rows take five person-days between them, and they repair the support measure, return 37 deals to an active pipeline, remove 10,400 contacts from the billable count, restore the invoice sync and prove the reconciliation, each tied to a named charter goal or, for the contacts, to a licence cost.
The costs are time and access. Each role gives a 45-minute interview, an administrator provisions access and pulls exports, a finance lead supplies the ledger extract, and the executive sponsor attends the intake and the review. A findings document stating 18 fails with evidence is also uncomfortable for the people who built the portal, and the audit is worth commissioning only where the business intends to act on the register.
RevOps HQ sells this audit as a fixed-scope service, which is the firm's interest in the method set out here. The case is strongest in a multi-hub portal bought for a goal that is visibly unmet, before a renewal that would lock in seats and tiers for another year, and before a migration that would carry every defect into the next system. It is weakest in a portal younger than six months, whose logs and stage histories are too short to read, and in a single-hub portal with a capable administrator, where HubSpot's own data quality tools and the tables above may be enough.
Limits of the Audit and of This Article
The audit is read-only, so it cannot test how a workflow would treat a record it has not yet met; it reads what automation did and infers the rest from configuration. It cannot see work done outside HubSpot, such as spreadsheets, the ledger beyond the export supplied, or tools the portal does not connect to. Interviews narrow that gap without closing it.
Every threshold is the firm's standard, chosen to make grading consistent and reproducible, and none is drawn from a study of portals; a business with reason for a different threshold records it in the charter and is graded against it. Log retention also bounds the evidence, at 90 days of action logs, six months of enrolment history and 30 days of standard audit log views.
HubSpot's behaviour, tier gates, limits and navigation are as documented in September and October 2026, and the linked knowledge base pages are authoritative where they differ from this text. The sample portal is sample data built to show the arithmetic; it describes no client, and its results show how the method grades a portal, not how portals in general perform.
Frequently Asked Questions
Audit Duration: How Long Does a HubSpot Audit Take?
The firm's planning range is 1 to 2 weeks for a standard audit of one portal, from access and intake in the first week to the review session at the end of the second. Portals with several hubs and integrations take longer, since each integration adds logs to read and each hub adds roles to interview.
Is a HubSpot Health Check the Same as a HubSpot Audit?
A health check is a configuration check: it asks whether settings exist and counts what is empty or duplicated. An audit as described here runs those tests and then tests the records against charter goals, which is how a portal configured correctly and still failing its job is found.
Can a HubSpot Audit Checklist Replace the Audit?
A capable administrator can run the catalogue above as a checklist with the linked documentation. What a checklist lacks is the charter mapping and the interviews, so it grades hygiene accurately and cannot say which failures matter to the business or in what order to fix them.
Does a HubSpot Portal Audit Change Anything in the Portal?
No configuration, data or automation is changed. Access is read-only throughout, every measurement is recorded with its method so that it can be reproduced, and the business decides afterwards what to remediate and who does the work.
Diagnosis: Why Is HubSpot Not Working After Implementation?
The symptoms table above traces the common complaints to mechanisms: stale and ownerless deals behind a distrusted forecast, two definitions behind conflicting pipeline figures, unemailed contacts behind a rising bill, and sync failures behind finance's doubts. Each mechanism is confirmed or excluded by named tests, and each one confirmed is a property of the portal rather than of the platform.
Does RevAudit Replace the Audit?
RevAudit re-runs measurable checks daily and alerts on regressions, which keeps the baseline current between audits. Its published feature list includes no intake, no contract or ledger reconciliation and no interviews, so the charter mapping and reconciliation tests stay with the audit. RevAudit is a product of Paul Maxwell, the founder of RevOps HQ.
In Summary
A HubSpot audit that reads only configuration grades the portal against its own settings, and a competently built portal passes that test whether or not it does its job. The method here starts from the job: a signed charter, a provisional charter from a 60-minute intake, or a technical baseline where the question is the state of the system. The context ladder records which tests the inputs made possible, and each test in the catalogue has an identifier, a place in HubSpot where it is read, a threshold stated as the firm's standard, and the evidence it keeps.
The findings register turns those results into decisions. Each row carries the measurement, grading, evidence, charter goal, consequence, recommendation, effort, benefit and dependencies, and the remediation sequence orders rows by benefit per person-day without running any row before its dependencies. On the sample portal that ordering put a half-day SLA fix and a half-day ownership repair ahead of the forecast rebuild, which would otherwise have been done twice.
The change to make first is to write down what the portal was bought to do before anyone measures it. Without that sentence an audit can report 46 measurements accurately and leave the spreadsheet forecast exactly where it was.
Sources
- HubSpot knowledge base, data and properties: https://knowledge.hubspot.com/properties/understand-the-property-editor, https://knowledge.hubspot.com/data-management/use-data-quality-tools, https://knowledge.hubspot.com/records/manage-duplicate-records, https://knowledge.hubspot.com/records/use-lifecycle-stages, https://knowledge.hubspot.com/records/view-record-property-history
- HubSpot knowledge base, integrations and automation: https://knowledge.hubspot.com/integrations/connect-and-use-hubspot-data-sync, https://knowledge.hubspot.com/workflows/understand-your-workflow-details-page, https://knowledge.hubspot.com/workflows/troubleshoot-common-automation-issues, https://knowledge.hubspot.com/workflows/workflow-enrollment-history
- HubSpot knowledge base, hubs: https://knowledge.hubspot.com/records/marketing-contacts, https://knowledge.hubspot.com/object-settings/set-up-pipeline-rules, https://knowledge.hubspot.com/properties/stage-calculated-properties, https://knowledge.hubspot.com/help-desk/set-sla-goals-in-help-desk, https://knowledge.hubspot.com/invoices/hubspots-default-invoice-properties, https://knowledge.hubspot.com/contracts/view-and-manage-contracts
- HubSpot knowledge base, access: https://knowledge.hubspot.com/account-management/manage-seats, https://knowledge.hubspot.com/account-management/view-and-export-account-activity-history, https://knowledge.hubspot.com/user-management/remove-hubspot-users
- HubSpot developer documentation: https://developers.hubspot.com/docs/developer-tooling/platform/usage-guidelines, https://developers.hubspot.com/docs/guides/apps/private-apps/overview
- Documentation and prices as read in September and October 2026.