Data quality
2 findings · ~10h if fixed separately
This wholly synthetic HubSpot fixture found deterministic access, CRM-model, data-quality, pipeline, automation, marketing and CMS configuration issues across all eight scored categories. The published overall result is grade B (86/100). The report contains no real customer records, traffic, backlink, revenue or conversion claims.
High-leverage changes you can start without a project plan. Effort figures are indicative.
Also in: Pipelines and process (4 findings)
Prioritised by severity, impact, effort, confidence and simple dependency order. Owner suggestions are heuristic; adjust to your team. Effort figures are indicative.
Mostly RevOps work
~14h indicative in this horizon
Mostly RevOps work
~16h indicative in this horizon
Mostly RevOps work
~12h indicative in this horizon
STANDARD
Reported tier: STANDARD. Tier fit could not be concluded because HubSpot did not report a recognised subscription tier. 2 relevant inventories were unavailable, so absence was not interpreted as feature underuse.
Add the tier you hold for each Hub and this report will show your licence at a glance. We only ever show what you confirm, never a guess.
These areas account for many of the high-impact findings.
2 findings · ~10h if fixed separately
2 findings · ~10h if fixed separately
4 findings · ~8h if fixed separately
Showing all findings across every owner. Pick a tab above to retell the same audit through one role's lens.
Search, filter, sort and expand findings. Results update without leaving this report.
14 findings shown after filtering and sorting.
Each category is scored out of 100 and contributes to the overall grade by its weight. The rationale explains what moved each score.
| Category | Grade | Score | Weight | Confidence | Why |
|---|---|---|---|---|---|
| Security and access | B | 86 | 20% | High | High super admin count. Many users have no primary team. |
| CRM data model | B | 80 | 15% | High | Contacts records have missing companies associations. Contacts lack a primary company association in the sample. |
| Data quality | B | 84 | 15% | High | contacts are largely stale. contacts ownership gaps. |
| Pipelines and process | B | 82 | 12% | High | Pipeline rule set hubspot-pipeline-rules-v1 (configuration and stage-health layers assessed separately). Long pipeline stage set. Invalid or ambiguous pipeline stage order. Open deals stuck for over 180 days. Conditional required-stage properties need manual verification. |
| Automation | A | 94 | 12% | High | Workflow rule set hubspot-workflow-rules-v1; configuration assessed, execution history not. Active but stale workflows. |
| Marketing setup | B | 88 | 10% | High | Campaign configuration ownership is incomplete. |
| CMS and assets | B | 82 | 8% | High | Domains without SSL enabled. High share of landing pages stuck in draft. |
| Governance | A | 100 | 8% | High | No major deterministic issues detected. |
Categories down, severities across. Cell intensity scales with finding count.
| Critical | High | Medium | Low | Info | Total | |
|---|---|---|---|---|---|---|
| Security and access | 0 | 0 | 1 | 1 | 0 | 2 |
| CRM data model | 0 | 0 | 2 | 0 | 0 | 2 |
| Data quality | 0 | 0 | 2 | 0 | 0 | 2 |
| Pipelines and process | 0 | 0 | 2 | 1 | 1 | 4 |
| Automation | 0 | 0 | 0 | 1 | 0 | 1 |
| Marketing setup | 0 | 0 | 1 | 0 | 0 | 1 |
| CMS and assets | 0 | 1 | 0 | 1 | 0 | 2 |
| Governance | 0 | 0 | 0 | 0 | 0 | 0 |
Higher is better. The shaded shape is this portal; the dashed line is the portfolio median for similarly-tiered HubSpot portals SpotCheck has audited.
Strongest category: Governance at 100/100. Lowest category: CRM data model at 80/100. A reliable compatible benchmark is not available for this chart.
| Category | This portal |
|---|---|
| Security and access | 86/100 |
| CRM data model | 80/100 |
| Data quality | 84/100 |
| Pipelines and process | 82/100 |
| Automation | 94/100 |
| Marketing setup | 88/100 |
| CMS and assets | 82/100 |
| Governance | 100/100 |
Benchmark values appear only for compatible cohorts with enough retained audits to be reliable.
Each dot is a finding. Top-left means quick wins and top-right means strategic projects. Use the chart or the finding controls below to jump to a finding.
10 plotted findings look like quick wins. Highest plotted impact: Domains without SSL enabled, 9/10 impact and about 1 hours. 1 finding lacked impact or effort estimates and are listed in the findings table instead.
| Finding | Severity | Impact | Effort | Owner |
|---|---|---|---|---|
| High super admin count | medium | 7/10 | 2 hours | IT/Security |
| Many users have no primary team | low | 4/10 | 1 hours | CRM Admin |
| Contacts records have missing companies associations | medium | 7/10 | 6 hours | RevOps |
| Contacts lack a primary company association in the sample | medium | 7/10 | 4 hours | CRM Admin |
| contacts are largely stale | medium | 8/10 | 6 hours | RevOps |
| contacts ownership gaps | medium | 8/10 | 4 hours | RevOps |
| Long pipeline stage set | low | 4/10 | 3 hours | RevOps |
| Invalid or ambiguous pipeline stage order | medium | 5/10 | 1 hours | RevOps |
| Open deals stuck for over 180 days | medium | 8/10 | 4 hours | Sales Manager |
| Active but stale workflows | low | 6/10 | 6 hours | RevOps |
| Campaign configuration ownership is incomplete | medium | 6/10 | 2 hours | Marketing Ops |
| Domains without SSL enabled | high | 9/10 | 1 hours | Web/CMS |
| High share of landing pages stuck in draft | low | 3/10 | 2 hours | Marketing Ops |
1 finding has no effort/impact estimate and is not plotted here. See the findings table for the full list.
Wholly synthetic golden fixture. Wholly synthetic fixture. No customer or anonymised production data is used.
Each deterministic rule records its outcome and the evidence it used. Checks that could not run are omitted here rather than shown as errors; they never count as a pass and never lower the score. The coverage summary above accounts for those gaps.
spotcheck-methodology-v2deterministic-rule-registry-v2hubspot-scorer-v8-independent-evidence-groupshubspot-score-evidence-v1deterministic-evidence-ledger-v2ece92e73e7855ea88549d10953a2c9487b68b92b26b4e02a4e1155fda8727abbCompare the observed aggregate Super Admin count with the portal-size band maximum.
hubspot.check.security.super-admin-count.v1Measure the aggregate share of active users without a primary team.
hubspot.check.security.primary-team-coverage.v1Compare hashed archived-owner references with the bounded CRM record sample.
hubspot.check.security.archived-owner-sample.v1Compare complete object counts with records not modified for three years.
hubspot.check.data-quality.stale-share.v1Compare complete object counts with records modified in the previous twelve months.
hubspot.check.data-quality.recent-activity-share.v1Compare complete object counts with complete unowned-record counts.
hubspot.check.data-quality.owner-coverage.v1Count validated deal and ticket pipeline definitions by object and name the observed pipelines.
hubspot.check.pipelines.inventory-size.v1Count stages in every validated deal and ticket pipeline and name the pipeline that exceeds SpotDev guidance.
hubspot.check.pipelines.stage-count.v1Validate closed-won probability 1 and closed-lost probability 0 on deal pipelines, and CLOSED ticketState where present.
hubspot.check.pipelines.terminal-probability.v1Check that open deal-stage probabilities do not decrease with display order when probability metadata is present.
hubspot.check.pipelines.probability-monotonicity.v1Detect duplicate active stage labels within a named pipeline.
hubspot.check.pipelines.duplicate-stage-label.v1Detect active stages whose label is empty.
hubspot.check.pipelines.empty-stage-label.v1Detect missing or duplicated displayOrder values among active stages.
hubspot.check.pipelines.invalid-stage-order.v1Count archived stages retained beside active stages in a named pipeline.
hubspot.check.pipelines.archived-stage-clutter.v1Measure unchanged open deals in the bounded, validated deal sample at the immutable audit timestamp as operating evidence.
hubspot.check.pipelines.stuck-deal-sample.v1Join the bounded deal sample to named pipeline stages and report stages unused in-sample as stage-health evidence.
hubspot.check.pipelines.empty-stage-sample.v1Emit a non-scored manual verification card because the public pipeline read contract does not expose conditional required-stage properties.
hubspot.check.pipelines.required-stage-enforcement.v1Count enabled workflows observed in the bounded workflow sample and cite named workflows.
hubspot.check.automation.enabled-workflow-count.v2Count enabled workflows in the bounded sample whose last-edit timestamp is more than twelve months before the audit timestamp.
hubspot.check.automation.stale-enabled-workflows.v2Count connected domains whose validated configuration reports HTTPS disabled.
hubspot.check.cms.transport-security.v1Measure the share of pattern redirects in the bounded redirect sample.
hubspot.check.cms.pattern-redirect-share.v2Measure the share of files marked public or searchable in the bounded file sample.
hubspot.check.cms.public-file-share.v2Measure the share of sampled site pages without a meta description.
hubspot.check.cms.site-page-metadata.v1Measure the share of sampled landing pages in the draft state.
hubspot.check.cms.landing-page-draft-share.v1Record validated marketing form capability coverage without inferring campaign performance.
hubspot.check.marketing.forms-coverage.v1Measure the share of sampled marketing forms with no configured fields.
hubspot.check.marketing.forms-field-hygiene.v1Record privacy-safe account and audit-context evidence separately from scored configuration findings.
hubspot.check.governance.account-evidence.v1Count validated custom roles beside the portal user inventory.
hubspot.check.governance.custom-roles.v1Count validated teams beside the portal user inventory.
hubspot.check.governance.teams-configured.v1Measure bounded source-object samples for missing target-object associations.
hubspot.check.associations.relationship-completeness.v1Separate any-company contact association evidence from primary-company association evidence.
hubspot.check.associations.primary-company-coverage.v1Read the portal-wide custom-property usage percentage from the validated limits inventory.
hubspot.check.crm-model.custom-property-limit-pressure.v1Compare configured association-label schema evidence with bounded association usage evidence.
hubspot.check.associations.label-adoption.v1Inspect the bounded deal sample for amount completeness and mixed-currency risk.
hubspot.check.sales-performance.currency-basis.v1Measure campaign configuration ownership in the validated campaign inventory; attribution counters remain non-scored associative evidence.
hubspot.check.marketing.campaign-performance.v1Separate published/draft/scheduled/archived content, aggregate CMS change history by pseudonymous actor and analyse redirect chains and loops.
hubspot.check.cms.governance-redirects.v1These records identify the bounded source used by each completed check. They contain labels and non-identifying page roles, not raw customer payloads. Sources that could not be collected are omitted.
An honest read on how complete this run was. Only categories with applicable, validated evidence are assessed. An optional capability without a confirmed grant is excluded, not treated as a pass or a customer defect. Independent checks inside a category still score when their own evidence is valid.
These are observed, non-scored review facts. Security events are not proof of compromise, and a missing property validation is not a defect until its business requirement is known.
Validation rules, sensitivity classifications and unique-value settings are separate facts. Uniqueness does not prove access control, encryption or protection.
These are observed, non-scored facts. Attribution is associative, behavioural evidence is aggregate only, and inactive commerce or CMS features are treated as not applicable.
SpotCheck® also runs a free website audit covering public performance evidence, SEO, accessibility and conversion readiness.
Audit a website