Most agencies audit their ad spend monthly and their account security never. That’s backwards, because a GoHighLevel agency account is a concentration of risk: one login stands in front of every client’s contact list, conversation history, and billing relationships. When something goes wrong, it rarely announces itself. A contact list quietly walks out with a departing sales rep, an old API key keeps working for a contractor you stopped paying last year, or a snapshot link you shared in a Facebook group in 2024 is still live.
Here’s the short version of the audit. Work through five questions: who can log in, what each person can do once inside, what software has API access, where your snapshots and exports are leaking, and whether you could recover if any of the first four answers turn out badly. Everything below is a pass through those five, in order, with the specific HighLevel settings to check. Block out ninety minutes a quarter and it’s done.
| Audit area | What to check | How often |
|---|---|---|
| Logins | Every user accounted for, 2FA on, no shared credentials | Quarterly, and at every offboarding |
| Permissions | Roles match actual jobs, only assigned data on for reps | Quarterly |
| API access | No v1 API keys, Private Integration tokens scoped and current | Quarterly |
| Snapshots and exports | No permanent share links you can’t name, export rights limited | Quarterly |
| Recoverability | Audit logs exported, independent backup running and tested | Monthly |
Who can log in, and how well is the door locked?
Start with a user inventory. Open your agency team list and every sub-account’s staff list and account for each name. The ones you can’t account for are the finding. Former employees, a freelancer from two projects ago, the client’s cousin who “helped with the website”: every stale login is standing access to client data, and agency-level stale logins are standing access to all of it.
Then check how those logins are protected. HighLevel supports two-factor authentication from each user’s profile security settings, with codes by SMS or an authenticator app. Prefer the app. SMS codes can be intercepted through SIM swaps, and the people most worth targeting at an agency (the owners and admins) are exactly the people whose phone numbers are easiest to find. If you run SaaS mode, the SaaS Configurator’s advanced settings let you switch on 2FA for newly signing-up sub-accounts, so your clients get the same protection by default.
Two habits round this out. No shared logins, ever, because a shared login makes your audit logs worthless and makes offboarding impossible. And make removal part of the same checklist as hiring: the day someone stops working with you is the day their user is deleted, not the quarter-end after.
What can each user actually do once inside?
HighLevel’s permission model has more range than most agencies use. A user belongs either to the agency or to specific sub-accounts, and is either an admin or a user. On top of that sit granular permissions, toggled per module, and the only assigned data setting, which limits a user to records assigned to them.
The audit question for each person is simple: does their access match their actual job? A booking assistant needs conversations and calendars, not the ability to delete pipelines. A commission-based sales rep should have only assigned data switched on, because a rep who can see the whole pipeline can export the whole pipeline on their way to a competitor. Contact export deserves particular attention since it’s the single fastest way for your client’s most valuable asset to leave the building. Keep it admin-only, and remember that the export itself is thinner than people assume, which cuts both ways: less useful as a backup, still plenty useful to a thief.
One more thing worth knowing exists: agency admins can use Login As User to enter the account as any team member. Useful for support, and also a reminder that agency admin is the role to guard most carefully, because it inherits everyone else’s view.
What has API access to your account?
People are only half the audit. The other half is software.
If your account still has API v1 keys floating around, that’s your biggest single finding. A v1 key grants unrestricted access to the account, v1 has reached end of life and is unmaintained, and keys don’t show up in a staff list, so nobody remembers they exist. An agency that ran a Zapier integration in 2023 through a v1 key and never revoked it has a permanent, unmonitored master key sitting in a third party’s database.
The replacement is Private Integration tokens, which work against API v2 and are scoped: you grant an integration only the specific permissions it needs, a webhook receiver gets contact read access and nothing else. During the audit, list every Private Integration, confirm you know what each one powers, delete the ones you can’t explain, and rotate tokens that were created by someone who no longer works for you. Do the same review for Marketplace apps installed on the account, reading the permission scopes each one holds rather than just the app name.
Where are your snapshots and exports leaking?
Snapshots are the sharing mechanism agencies use most and audit least. A share link is access, and the different link types carry very different risk. A permanent link can be imported by anyone who has the URL, unlimited times, until you revoke it. One-time links expire after a single import. Agency-restricted and sub-account-restricted links only work for the specific accounts you list. If you’ve ever dropped a permanent link into a course, a community, or a DM, assume it’s still circulating, and revoke anything you can’t name a current reason for.
The other snapshot risk points inward. Pushing a snapshot update to client sub-accounts overwrites the linked assets in every account that receives it, including any customizations a client made to their copy. Treat a push like a production deployment: know exactly what’s in it and who’s getting it. And keep in mind what snapshots contain in the first place. They copy configuration, not contacts, conversations, or opportunities, so a leaked snapshot exposes your build, while a leaked export exposes your client’s business. Both matter; they’re different incidents.
Would you know if something changed?
Detection is where most agency audits stop short. HighLevel’s audit logs record changes to contacts, opportunities, notes, tasks, custom values, tags, and custom objects, each entry stamped with the user, the module, and the time. When a client calls asking why 400 contacts lost their tags, this is where the answer lives.
The catch is retention: logs stay in the app for 60 days, then they’re gone. If a problem takes longer than that to surface, and data problems often do, the trail has already ended. The fix costs nothing: put a recurring task on the calendar to export audit logs monthly and file them wherever you keep client records. Sixty days of memory becomes a permanent one.
Could you recover if the audit fails?
Every control above can be bypassed by the one actor no permission system stops: an admin having a bad day, including you. Misclicks, bad imports, a workflow edit that breaks three client campaigns. So the last audit question is the honest one: if data disappeared this afternoon, what exactly would you get back?
Inside HighLevel, the answer is a patchwork of windows. Deleted contacts can be restored for 60 days. A deleted sub-account has a 24-hour undo, held by the agency. Workflows, funnels, and everything else each have their own clocks or none at all, and HighLevel’s own infrastructure backups, roughly 7 days of database-level copies kept for platform disaster recovery, are not something you can request a restore from. Past the windows, the platform’s answer is no.
Closing that gap is why we built GHLArmor, and since it’s our product, weigh the recommendation accordingly. It’s the first backup approved by the HighLevel Marketplace, continuously copying contacts, conversations, custom fields, opportunities, and workflows to storage outside HighLevel, with one-click restores when something breaks. In audit terms it’s the compensating control for everything the checklist can’t prevent, and the only line item here that still works when the failure is the account itself, as clients of shuttered agencies learn the hard way. Whatever tool you use, test a restore once a quarter. An untested backup is a hope, not a control.
Run the five questions again in three months. The first audit is the slow one; after that it’s maintenance.
Frequently asked questions
Does HighLevel support two-factor authentication? Yes. Every user can enable 2FA from their profile’s security settings, with a code delivered by SMS or generated by an authenticator app. The authenticator app is the stronger option. Agencies running SaaS mode can also require 2FA for newly signing-up SaaS sub-accounts through the SaaS Configurator’s advanced settings.
Can I see who changed something in my HighLevel account? Partly. HighLevel’s audit logs record changes to contacts, opportunities, notes, tasks, custom values, tags, and custom objects, with the user, module, and timestamp for each entry. Logs are kept in the app for 60 days, so export them on a schedule if you need a longer trail.
Are old HighLevel API keys safe to keep using? No. API keys belong to API v1, which has reached end of life, and they grant unrestricted access to everything in the account. Replace them with Private Integration tokens, which are scoped to only the permissions an integration actually needs, and rotate those tokens when staff or vendors leave.
How do I stop a staff member from exporting my HighLevel contact list? Give them the user role rather than admin, then trim their granular permissions so the contacts module and account tools are off, and enable the only assigned data toggle so they see just their own records. Contact export is an admin-level capability, so a properly scoped user role cannot walk away with the full list.
Do HighLevel snapshots create a security risk? They can. A permanent snapshot share link can be imported by anyone who has the URL, and pushing snapshot updates overwrites the linked assets in every client sub-account that receives them. Use one-time or agency-restricted links, keep an inventory of active links, and treat push updates with the same care as a production deployment.