How to Manage HubSpot Permission Sets and Seats (Without Breaking Your Portal)
- Kacy Bartleigh

- Jun 8
- 3 min read
If HubSpot is the operating system powering your marketing and sales teams, permissions are the guardrails that keep everything running smoothly.

But here’s what we see all the time with startup teams:
Someone new joins the company and gets added
Someone leaves but isn’t deleted
An agency gets temporary access everyone forgets to manage
A sales rep suddenly can’t see the right contacts and no one knows why
HubSpot portals easily turn into a messy patchwork of permissions that no one fully understands. This isn’t just inconvenient. Poor permission management can create performance issues, reporting problems, and even security risks.
The good news? HubSpot’s Permission Sets and Seat Types make it easier than ever to organize access if you set them up correctly.
Let’s walk through how to manage them strategically.
First, Understand the Difference: Seats vs. Permission Sets
Before diving into setup, it helps to clarify two key concepts.
HubSpot Seats
Seats determine what level of product access a user has based on licensing.
Common examples include:
Core Seat (Starter/Professional/Enterprise access): Full product functionality for marketing, sales, or service teams
View-Only Seat: Users can view data but not edit it (perfect for executives)
Partner Seat: Designed for agencies or consultants
Free Seat: Basic portal access with limited capabilities
In short: Seats define the license level.
Permission Sets
Permission sets define what a specific user can actually do inside HubSpot.
For example:
A marketing manager might have permission to:
Publish blog posts
Launch workflows
Edit landing pages
A sales rep might only be able to:
Manage their contacts
Log activities
Create deals
In short: Permission sets control capabilities.
Step-by-Step: How to Manage HubSpot Permission Sets
Here’s the process as we typically implement it for clients.
Step 1: Audit Your Current Users
Start with a quick cleanup.
Navigate to:
Settings [icon] → Users & Teams
Ask yourself a few basic questions:
Who still needs access?
Who has admin permissions unnecessarily?
Are there inactive users or old contractors still listed?
This quick audit often reveals surprising access gaps. One of the first things we do during a marketing audit is identify unused users or outdated permissions. It’s low-effort cleanup that dramatically improves portal security.
Step 2: Assign the Right Seat Type
Next, confirm each user has the correct seat license. By hovering over the name, select Edit Permissions and any edits needed can be made here.
This prevents unnecessary licensing costs while keeping access aligned with responsibilities.
Step 3: Create Permission Sets by Role
HubSpot’s modern permission structure shines here. Instead of configuring every user individually, create role-based permission sets. Scroll up to the tabs at the top and select Permission sets. Then, click the button to Create permission set.
Creating these sets once saves hours of admin work later.
Step 4: Assign Users to Permission Sets
After building permission sets, assign them to users.
Head back to Users tab
Hover over the user
Select Actions dropdown
Select Manage permissions
Click Assign permission set
This approach scales easily as your team grows.
[Optional] Step 5: Use Teams for Data Visibility
As an added level of security, use HubSpot teams to control who can see what records.
For example:
Sales teams can see only their pipeline
Marketing teams can see all contacts
Customer success teams can access customer records
Using teams settings alongside permission sets ensures your CRM stays organized. Explore the Teams tab at the top for this feature.
Common HubSpot Permission Mistakes (and How to Avoid Them)
Here are the most frequent issues we see.
Too Many Super Admins
Super Admin access should be extremely limited.
Best practice:
2–3 admins maximum
One marketing owner
One operations owner
One backup
Everyone else should use role-based permissions.
No Permission Structure
If every user has custom permissions, your portal becomes impossible to manage.
Instead, use standardized permission sets.
Giving Agencies Full Access
Agencies often don’t need CRM editing rights.
Instead provide access only to:
Campaign tools
Ads
Landing pages
Reporting
Your CRM data should remain protected.
Our Recommended HubSpot Permission Framework
For most startup teams, we recommend five core roles:
Super Admin
Marketing Manager
Sales Rep
Sales Manager
View-Only Executive
This simple structure keeps access clean and scalable. And when your marketing stack grows more complex, that structure becomes invaluable.
At Wheels Up Collective, we often start new engagements with a marketing audit that includes HubSpot architecture and permissions. We find that basic operational clarity goes a long way to fueling better campaigns and faster growth.
HubSpot permissions are one of those things you only notice when they’re really broken, and by then inefficiencies will have piled up behind the scenes. You’ll spend way too much time fixing access problems than launching campaigns. And we know your marketing team has better things to do. Set permissions up properly now, and your team will barely think about them again.




