Shared data

Everything Tendal touches, in one table.

Required scopes are the ones without which there is no audit. Optional scopes sharpen it: if your plan does not include one, Tendal runs without it and names what it could not measure. Last updated 30 July 2026.

Nothing is written back. Tendal holds no write scope it could use: it asks for no permission to create, change or delete a record, a property or a user. One exception, marked below: HubSpot publishes no read-only version of the workflows scope, so reading workflows means being granted write as well. Tendal only ever reads it, it is optional, and declining it costs you the automation signals and nothing else.

Required

ScopeReadsWhyWhat leaves your portal
crm.objects.users.readUsersThe list of users and the seat assigned to each. This is the audit.Counts per seat type. Email addresses are read to name a user in the result on screen, and are not stored.
settings.users.readUser settingsWhether a user is active or deactivated, and their permission set.Counts only.
crm.objects.owners.readOwnersJoins users to record ownership, including owners of deactivated users.Counts only.
crm.objects.contacts.readContactsHow many contacts each user touched in the window, as an activity signal.Counts only. No contact record is copied.
crm.objects.deals.readDealsHow many deals each user worked, as an activity signal.Counts only. No deal record is copied.

Optional

ScopeReadsWhyWhat leaves your portal
automation.sequences.readSequencesWho sends sequences. A sender needs a paid seat, so this protects users from a wrong downgrade.Counts only.
automationread + writeWorkflowsWhich workflows enrol sequences, and who they send as. HubSpot publishes no read-only version of this scope, so granting it also grants write. Tendal only ever reads. Decline it and every other pillar still works.Counts only.
settings.users.teams.readTeamsWho is in each team. A workflow notification can be addressed to a team rather than a named person, so without this Tendal cannot tell a team that still has members from one that has none. It then says the check was incomplete instead of reporting a clean result.Counts only.
scheduler.meetings.meeting-link.readMeeting linksPersonal versus round-robin links, as an activity signal.Counts only.
crm.objects.forecasts.readForecastsWhether a user submits forecasts, which is a Sales Hub seat signal.Counts only.
crm.objects.leads.readLeadsHow many leads a user owns, so prospecting counts as work. Without it a prospector reads as idle and the seat recommendation is wrong.Counts only.
crm.objects.quotes.readQuotesHow many quotes a user builds, which is Sales Hub work the seat question turns on.Counts only.
ticketsTicketsHow many tickets a user owns and works, so Service work counts. Without it a support agent reads as idle, because none of the other signals can see a ticket.Counts only. No ticket content is copied.
crm.schemas.custom.readCustom object schemasWhich custom object types exist, so activity on them is not missed.Counts only.
crm.objects.custom.readCustom object recordsHow many custom-object records each user touched.Counts only.
account-info.security.readLogin historyWhen a user last logged in. Enterprise-only: on smaller plans the result says the signal is missing rather than counting those users as inactive.Counts only.

The distinction that matters

Tendal reads records in order to count them. A contact is read to answer "how many contacts did this user touch", and the answer that leaves your portal is a number. The contact itself is not copied, stored or transmitted anywhere.

The one exception is user email addresses, which are read so the result can say which user is on a seat they do not use. They are shown on screen and are not written to the stored history, which is built so it cannot carry them.

What we keep, and for how long, is set out in the privacy policy.

See the output on a synthetic portal