Skip to content
Capra Digitals

How to audit a HubSpot portal in 90 minutes

The first ninety minutes in an unfamiliar portal decide whether the rest of the engagement is calm or chaotic. Here is the exact order we work in.

Published 12 May 2026 · Updated 4 August 2026 · 9 min read · Capra Digitals

The short answer

To audit a HubSpot portal in 90 minutes, work in six fixed passes: 15 minutes on data quality (duplicates, blank required properties, record counts by object), 20 minutes on workflows (active count, enrolment triggers, errored actions, anything unnamed), 15 minutes on integrations and API health, 10 minutes on marketing contact usage and billing exposure, 20 minutes on reporting (do two dashboards for the same metric agree?), and 10 minutes on users, permissions and deleted-record settings. Write findings as you go, ranked by cost, not by tidiness. A 90-minute pass will not fix anything, but it reliably tells you which of the six areas deserves a full engagement.

Why 90 minutes is the right length

A full audit is ten to twelve business days and produces a report someone actually has to read. That is the right deliverable when a client has already decided to invest. It is the wrong deliverable when someone just wants to know whether their portal is in trouble.

Ninety minutes is enough to see every category of problem and none of the detail. That is a feature. You are not trying to catalogue 400 issues — you are trying to work out which of six areas is on fire, so the next conversation is about the right thing.

Pass 1 — Data quality (15 minutes)

Start with record counts by object and compare them to what the business thinks it has. A company that says 'about 20,000 contacts' and has 61,000 is telling you something about imports nobody owns.

  • Run the duplicate management tool for contacts and companies and note the count, not the names.
  • Check the fill rate on the three properties that drive routing or reporting — usually lifecycle stage, owner and country.
  • Sort contacts by create date descending and look at the last 200. Imports leave fingerprints.
  • Look at how many properties exist. Over 300 custom properties on a mid-market portal almost always means nobody is deprecating anything.

Pass 2 — Workflows and automation (20 minutes)

Sort workflows by last-modified date. The ones nobody has touched in eighteen months are usually still enrolling contacts. Then sort by enrolment count — a workflow that has enrolled six people in two years is dead weight; a workflow enrolling thousands with no exit criteria is a bill.

  • Filter for workflows with errors and open the three most recent.
  • Count workflows with no naming convention. If more than a third are untitled or named 'Copy of…', governance is the real problem.
  • Check for re-enrolment turned on where it should not be, and for date-based delays that expired years ago.

Pass 3 — Integrations and API health (15 minutes)

What to checkWhereWhat bad looks like
Connected appsSettings → IntegrationsApps installed by ex-employees, still syncing
API call usageAccount → MonitoringSustained spikes with no known cause
Sync errorsEach app's sync dashboardThousands of failing records nobody sees
WebhooksWorkflow actionsEndpoints pointing at retired systems

Pass 4 — Marketing contacts and billing exposure (10 minutes)

This pass pays for the audit more often than any other. Check how many contacts are set to marketing, what automatically sets them to marketing, and whether anyone has ever run the non-marketing cleanup. An import that flipped 30,000 unengaged records to marketing is a five-figure annual line item that nobody chose.

Pass 5 — Reporting (20 minutes)

Pick one metric leadership quotes weekly — usually pipeline created or MQLs — and find every place it appears. If two dashboards disagree, the definitions differ, and every strategy conversation downstream is negotiating with noise.

Then check date properties. Reports built on 'create date' when the business means 'became an opportunity date' are the most common silent error we find.

Pass 6 — Users, permissions and hygiene (10 minutes)

  • Deactivated employees still holding record ownership.
  • Super admin count. More than three on a 40-seat portal is a risk, not a convenience.
  • Whether anyone can delete records in bulk, and whether there is a recovery process.

Writing it up so it gets acted on

Rank findings by annual cost or risk, not by how untidy they are. Three lines per finding: what it is, what it costs, what fixing it takes. Anything that cannot be expressed that way goes in an appendix.

Common mistakes

  • Starting with workflows because they are interesting. Data quality first — bad data explains most broken automation.
  • Fixing things during the audit. Change one setting and you no longer know what the baseline was.
  • Producing a list of 200 findings. Nobody actions a list of 200 findings.
  • Auditing without asking what leadership believes the numbers are. The gap between belief and reality is the finding.

Questions

People also ask

Do you need super admin access to audit a HubSpot portal?

Read-only access covers most of a 90-minute pass, but marketing contact settings, API monitoring and user permissions need admin visibility. We ask for super admin, make no changes, and confirm that in writing before we start.

How is this different from a full HubSpot audit?

A 90-minute pass tells you which areas are broken. Our full audit takes ten to twelve business days, covers every object, workflow and integration in detail, and comes with a prioritised remediation plan and fixed-price proposal.

How often should a portal be audited?

Annually for a stable portal, quarterly if you are running high-volume campaigns or integrating new systems, and always before a migration, a hub upgrade or a change of agency.

Keep reading

Next step

Want this done in your portal, not just explained?

Bring us the portal as it is. We will tell you what is worth fixing, what it costs and in what order.