Everything Tendal touches, in one table.
Required scopes are the ones without which there is no audit. Optional scopes sharpen it: if your plan does not include one, Tendal runs without it and names what it could not measure. Last updated 30 July 2026.
Nothing is written back. Tendal holds no write scope it could use: it asks for no permission to create, change or delete a record, a property or a user. One exception, marked below: HubSpot publishes no read-only version of the workflows scope, so reading workflows means being granted write as well. Tendal only ever reads it, it is optional, and declining it costs you the automation signals and nothing else.
Required
| Scope | Reads | Why | What leaves your portal |
|---|---|---|---|
crm.objects.users.read | Users | The list of users and the seat assigned to each. This is the audit. | Counts per seat type. Email addresses are read to name a user in the result on screen, and are not stored. |
settings.users.read | User settings | Whether a user is active or deactivated, and their permission set. | Counts only. |
crm.objects.owners.read | Owners | Joins users to record ownership, including owners of deactivated users. | Counts only. |
crm.objects.contacts.read | Contacts | How many contacts each user touched in the window, as an activity signal. | Counts only. No contact record is copied. |
crm.objects.deals.read | Deals | How many deals each user worked, as an activity signal. | Counts only. No deal record is copied. |
Optional
| Scope | Reads | Why | What leaves your portal |
|---|---|---|---|
automation.sequences.read | Sequences | Who sends sequences. A sender needs a paid seat, so this protects users from a wrong downgrade. | Counts only. |
automationread + write | Workflows | Which workflows enrol sequences, and who they send as. HubSpot publishes no read-only version of this scope, so granting it also grants write. Tendal only ever reads. Decline it and every other pillar still works. | Counts only. |
settings.users.teams.read | Teams | Who is in each team. A workflow notification can be addressed to a team rather than a named person, so without this Tendal cannot tell a team that still has members from one that has none. It then says the check was incomplete instead of reporting a clean result. | Counts only. |
scheduler.meetings.meeting-link.read | Meeting links | Personal versus round-robin links, as an activity signal. | Counts only. |
crm.objects.forecasts.read | Forecasts | Whether a user submits forecasts, which is a Sales Hub seat signal. | Counts only. |
crm.objects.leads.read | Leads | How many leads a user owns, so prospecting counts as work. Without it a prospector reads as idle and the seat recommendation is wrong. | Counts only. |
crm.objects.quotes.read | Quotes | How many quotes a user builds, which is Sales Hub work the seat question turns on. | Counts only. |
tickets | Tickets | How many tickets a user owns and works, so Service work counts. Without it a support agent reads as idle, because none of the other signals can see a ticket. | Counts only. No ticket content is copied. |
crm.schemas.custom.read | Custom object schemas | Which custom object types exist, so activity on them is not missed. | Counts only. |
crm.objects.custom.read | Custom object records | How many custom-object records each user touched. | Counts only. |
account-info.security.read | Login history | When a user last logged in. Enterprise-only: on smaller plans the result says the signal is missing rather than counting those users as inactive. | Counts only. |
The distinction that matters
Tendal reads records in order to count them. A contact is read to answer "how many contacts did this user touch", and the answer that leaves your portal is a number. The contact itself is not copied, stored or transmitted anywhere.
The one exception is user email addresses, which are read so the result can say which user is on a seat they do not use. They are shown on screen and are not written to the stored history, which is built so it cannot carry them.
What we keep, and for how long, is set out in the privacy policy.