Today, when a Super Admin uses Settings → Users & Teams → Log in as user, HubSpot automatically emails that user to say an admin logged into their profile.
This is documented behavior:
An email will be sent to the user to notify them that an admin logged into their profile.
(from the “Log in as another user” documentation)
In practice, this creates friction for routine internal support and troubleshooting:
- Super Admins often impersonate users to:
- Validate what they can see/do
- Reproduce issues
- Help configure views or settings
- Every impersonation triggers an email that looks like a security event.
- Users frequently ask “Why did I get this email? Is something wrong?”, which generates unnecessary noise and concern.
We understand the importance of auditability and agree that impersonation should be logged. What we’re asking for is control over the user‑facing notification, not to remove traceability.
Requested enhancements
Please add configuration options so Super Admins can choose how this behaves, for example:
-
Portal‑level setting for “Log in as user” notifications:
- Always email the user (current default)
- Don’t email the user, but log the event in security/audit logs
- (Optionally) notify only admins/security owners instead of the impersonated user
-
Option to change the channel or wording, such as:
- Use an in‑app notification instead of an email, or
- Allow customization of the email text so we can clearly indicate this was an internal support action, not a suspicious login.
We’d still expect:
- Impersonation events to be fully logged (who impersonated whom, and when)
- Existing restrictions to remain (e.g., cannot log in as another Super Admin)
The key ask is: let accounts decide whether that impersonation email should go directly to the end user, or be handled differently, so routine admin troubleshooting doesn’t look like a security incident every time.