Treat HubSpot/system‑initiated changes separately from user activity in Audit Logs and asset history

Description

We’re running into serious auditing and asset‑management confusion because HubSpot’s backend/system updates are being logged as if they were performed by our users, including users that have been deactivated for years.

What we’re seeing

  • In the centralized Audit Logs, especially under the Content → Email category, we see large clusters of events all at the same timestamp (for example, on 3/9/2026).
  • Those events are attributed in the “User” / “Modified by” field to people who:
    • Have been deactivated for years, and
    • Have no recent logins in the user‑level audit/log history.
  • We’ve also seen past cases where a HubSpot update (migration, backend change, etc.) made it appear that “all of our assets were updated” at the same time, again as if done by our users.

From an admin’s point of view, this is completely unexpected and makes it look like deactivated users are suddenly active again, or that our own team bulk‑edited assets when in reality it was a HubSpot/system process.

Why this is a problem

  • It breaks our ability to trust the “last touched” history for emails, content, automations, and reports.
  • It makes it very hard to answer basic questions like “When did we last edit this asset or Workflow, and who did it?”
  • It clutters security and compliance reviews, because we have to manually verify that deactivated users did not in fact regain access or make changes.
  • It creates confusion any time we see big clusters of changes all attributed to our users at the same timestamp, when those changes actually came from HubSpot/system activity.

What we’re asking for

  1. Clear separation of actor types

    • Log HubSpot‑initiated/backend/system/migration actions as being done by a distinct “system” or “HubSpot” actor, not by our user accounts.
    • Do not attribute those actions to deactivated or legacy human users.
  2. Accurate attribution in Audit Logs and asset history

    • In the centralized Audit Log, show clearly when an event was:
      • Performed by a human user, vs.
      • Performed by a HubSpot/system process, vs.
      • Performed by an integration/connector.
    • Apply the same principle anywhere we see “last updated by” or similar fields on assets, emails, workflows, and other tools.
  3. Filter and visibility controls for admins

    • Allow us to easily filter OUT system/HubSpot actions when we are reviewing human user activity.
    • Conversely, allow filters that show ONLY system/HubSpot actions, for troubleshooting and change‑management purposes.

Nice‑to‑have enhancements

  • A clearer label or column in Audit Logs (and/or exports) for “Source” or “Actor type” (User vs System vs Integration), so it’s obvious what we’re looking at.
  • Backfill where possible for recent system changes, so we can retroactively distinguish them from real user edits.

This change would make the Audit Log and asset history far more reliable for admins, security teams, and anyone managing content/automation at scale. Right now, system‑initiated updates appearing as if they were done by our (often deactivated) users makes auditing and day‑to‑day management unnecessarily difficult.

This is a great and concise post and I absolutely support the need for updates like this to the audit log.