Read-only, and specific about it.
Tendal asks for the narrowest set of scopes that can answer one question: is each person on the cheapest seat that still lets them do their job.
It never writes.
Not as a setting you could switch: there is no code in Tendal that changes anything. It asks for no permission to create, alter or delete a record, a property or a user. Recommendations are for you to act on in HubSpot, by hand, if you agree with them.
One honest exception, because you will see it on HubSpot's approval screen. Reading your workflows needs the scope HubSpot calls automation, and HubSpot publishes no read-only version of it, so approving it grants write as well. Tendal only ever reads. It is optional: decline it and you lose the automation signals, nothing else. Every scope is listed with its reason on the shared data page.
Nothing is installed in your portal. No agent, no embedded card, no background job running inside HubSpot. Tendal is an outside reader that connects, counts, and disconnects.
Disconnecting is done from your own HubSpot account, under connected apps. It takes effect immediately and needs nothing from us.
Everything it asks for, and why.
Required scopes are the ones without which there is no audit. Optional scopes sharpen it: if your plan does not include one, Tendal runs without it and names what it could not measure.
Required
Optional
Counts, not your CRM.
Tendal reads records to count them. It does not copy them. What persists between scans is deliberately thin.
Kept: your portal id, an encrypted token that lets Tendal reconnect, and one snapshot per scan holding derived figures: seat counts, the saving, how many users fell in each category. That is what makes a trend possible.
Not kept: your contacts, companies, deals or tickets. The trend history is built so it cannot carry personal data: the audit names users by email while it runs, and the stored snapshot does not, so neither the history nor the alerts derived from it can leak one.
Access tokens are never stored. Only the refresh token is, encrypted at rest. Every scan mints a short-lived access token and discards it.
Alert destinations are encrypted the same way: a Slack webhook because it is a credential, an email address because it is personal data.
Read the output before you connect anything.
The sample runs against a synthetic portal. Every figure in it is invented and no real account is contacted.
See a sample