I would be mind-blown if someone hasn’t already created a post about this, so if someone has, feel free to let me know. Right now, as far as I can tell, the fairly basic action of creating an association label is a feature that is only exposed to Super Admins. That is a massive security concern. In order for our users to use this feature, we now have to give them complete and unfettered access to our Hubspot account? We (as I’d imagine most security-concious organizations do) heavily restrict access to the SuperAdmin role due to the dangerous actions that can be performed with that role and don’t even allow our Hubspot Administrator to have SuperAdmin access by-default (She has nearly every other permission besides user management, bulk data export access, and a few other potentially hazardous actions). Historically Hubspot’s granular permissions have been really solid and allow for least-privilege principles to be applied, but this is a big outlier that (IMHO) needs to be fixed ASAP. Please expose association label creation as a configurable permission for other roles besides the SuperAdmin role.
Great idea, @JPetrovics … and one desperately needed! Thanks for submitting ![]()
I completely support this idea. It should be possible to allow creation of certain objects, labels, associations that is currently possible only as Super Admin. Right now, this is possible only as Super Admin (under Professional License). This is not a prudent set up and exposes critical data that the Super Admin would not want to hand over to an Admin. Kindly make this feature available asap.
Agreed, in fact I can’t believe more people haven’t asked for this to be actioned… Surely big organisations using this platform would be sensitie to the capabilities of a Super Admin role be assigned to a user without understanding the risk. As a new cutomer, we will now need to put a service desk process in place to request elevation to Super Admin at the time the user needs to work on these associations.
We too need this as a permission setting for admin users besides super admins.
I just stumbled across this idea and I’m honestly shocked that this isn’t already possible in HubSpot. At a company level, it’s crucial to protect sensitive data from unnecessary access – including from internal IT/admin teams. Having to grant full Super Admin rights just to manage association labels is simply not acceptable in a security-conscious environment. Exposing label creation as a dedicated, granular permission would be a major step toward proper least-privilege governance.