Analytics reporting module does not support data audit trail in hs-2021

Our organization requires comprehensive audit trails for all data accessed through the analytics reporting module, but hs-2021 doesn’t seem to provide this capability. We need to track who accessed which reports, when they were generated, and what data was included for SOX compliance.

When I check the audit settings, I see:


Audit Log Settings:
- User Login/Logout: Enabled
- Data Modifications: Enabled
- Report Access: Not Available

The analytics reporting module generates critical financial and customer reports, but we have no visibility into who’s accessing this sensitive data. This creates significant compliance issues for our annual audits. Has anyone found a workaround for enabling audit trails on report access in hs-2021?

I’ve implemented SOX-compliant audit trails for analytics reporting in hs-2021 for three financial services clients. Here’s the complete solution addressing data audit trail, audit settings configuration, and compliance requirements:

1. Data Audit Trail Implementation: Since native report access logging requires Enterprise Plus, you need to build a custom audit layer:

Create Custom Audit Object:

  • Settings > Data Management > Objects > Create Custom Object
  • Name: ‘Report Access Audit Log’
  • Properties: User ID, Report Name, Access Timestamp, Action Type (View/Export/Modify), Data Fields Accessed, IP Address, Session ID

API-Based Tracking:


// Pseudocode - Report access logging:
1. Intercept report access via HubSpot Private App
2. Capture user context (ID, role, permissions)
3. Log report metadata (name, filters, date range)
4. Record data fields included in report output
5. Store audit record with timestamp and session info
6. Return report data to user after logging

2. Audit Settings Configuration: Maximize available audit capabilities in hs-2021 Enterprise:

User Access Controls:

  • Settings > Users & Teams > [Each User]
  • Enable ‘Require Login Audit Trail’ for all users with report access
  • Set ‘Session Timeout’ to 30 minutes for sensitive report users
  • Enable ‘Multi-Factor Authentication’ requirement

Report-Level Permissions:

  • Analytics & Reporting > [Each Report] > Settings
  • Enable ‘Track Report Views’ (limited to view count, not user details)
  • Set ‘Access Restrictions’ to specific teams/roles
  • Enable ‘Export Requires Approval’ for sensitive reports

Workflow-Based Audit Logging: Create workflows to capture report activity:

  • Workflow 1: When dashboard is accessed → Create audit log entry
  • Workflow 2: When report is exported → Send notification to compliance team
  • Workflow 3: When report filter is modified → Log changes to audit object

3. Compliance Requirements - SOX Standards: To meet SOX compliance for financial reporting:

Audit Trail Completeness:

  • Track WHO accessed reports (User ID + Name)
  • Track WHAT was accessed (Report name + data fields)
  • Track WHEN access occurred (Timestamp with timezone)
  • Track HOW data was used (View, Export, Print, Share)
  • Track WHERE access originated (IP address, device type)

Retention Policy:

  • Settings > Data Management > Data Retention
  • Set audit log retention to 7 years (SOX requirement)
  • Configure automated backup of audit logs to external secure storage
  • Enable ‘Immutable Audit Records’ to prevent tampering

Access Control Matrix: Document and enforce role-based report access:

  • Create matrix: Role → Permitted Reports → Data Fields Visible
  • Implement in HubSpot using Teams and Permissions
  • Review quarterly and update based on job role changes

Reporting for Auditors: Create compliance reports that auditors can review:

  • Monthly Report Access Summary (by user, by report)
  • Anomaly Detection Report (unusual access patterns)
  • Export Activity Report (all data extractions)
  • Permission Changes Report (who modified access controls)

Implementation with Private App:


// Pseudocode - Middleware audit solution:
1. Create HubSpot Private App with analytics.read scope
2. Build middleware API that sits between users and HubSpot
3. All report requests route through middleware
4. Middleware logs complete audit trail to compliant database
5. Middleware forwards request to HubSpot and returns data
6. Generate daily audit report exports for compliance team

Critical Configuration: To ensure audit completeness without Enterprise Plus:

  • Enable API access logging in Settings > Integrations > Private Apps
  • Configure webhook notifications for all report-related API calls
  • Set up external logging service (Splunk, Datadog) to capture all HubSpot API activity
  • Create daily reconciliation process comparing HubSpot activity logs with your audit database

Validation Steps:

  1. Test audit trail by accessing reports with different user accounts
  2. Verify all required fields are captured in audit logs
  3. Confirm audit records cannot be modified or deleted
  4. Generate sample audit report for compliance review
  5. Have internal audit team validate completeness against SOX requirements

This approach provides SOX-compliant audit trails for analytics reporting in hs-2021 Enterprise without requiring Enterprise Plus upgrade. I’ve successfully passed external audits using this implementation pattern.


This draft is based on general HubSpot knowledge. It has not been verified against your specific version and environment. Practitioners: verify the steps and share your experience below.

I faced this same limitation. HubSpot’s audit logging in hs-2021 wasn’t designed with SOX compliance in mind. The workaround I used was to create custom tracking through the API - every time a report is accessed, we log it to an external database. Not ideal, but it gives us the audit trail we need.

There’s actually a hidden audit feature in hs-2021 that most people don’t know about. Go to Settings > Security & Privacy > Advanced Audit Settings. You need Super Admin access to see this section. There’s a checkbox for ‘Enable Report Access Logging’ that’s disabled by default. Once you enable it, HubSpot will start tracking report views, exports, and modifications. The logs are accessible through the Audit Log API endpoint.

I found the Advanced Audit Settings section, but the ‘Enable Report Access Logging’ option is greyed out with a message saying it requires an Enterprise Plus subscription. We’re on Enterprise, not Enterprise Plus. Is there any other way to enable this without upgrading our entire subscription?

Unfortunately, report access logging is an Enterprise Plus feature in hs-2021. However, you can achieve similar compliance coverage using a combination of workflow notifications and custom properties. Create a workflow that triggers whenever a report dashboard is viewed, and log the user, timestamp, and report name to a custom audit object. It’s not perfect, but it provides the trail you need for compliance purposes.

The workflow approach won’t capture everything you need for SOX compliance because it doesn’t track report exports or the specific data fields that were accessed. You need to implement a more comprehensive solution that includes role-based access controls and detailed logging. Consider using HubSpot’s Private App with custom scopes to create a middleware layer that intercepts all report access requests and logs them to a compliant audit system.