HighLevel CRM - Access & permissions
Elevale uses OAuth 2.0 to read metrics from HighLevel CRM. Elevale does not modify data in the external system. Tokens and keys are encrypted server-side after validation.
Who can connect
Workspace admins and users with permission to manage Workspace Settings integrations.
Connections are managed from Workspace Settings → Integrations.
Requires [Business+] on your workspace plan.
What Elevale accesses
Read-only metrics exposed as KPI data points (see the Data points article).
Connection metadata (account IDs, property IDs, organisation tenants) needed for sync.
No write access to campaigns, repositories, accounting records, or CRM objects unless the provider API requires it for authentication only.
Before you connect
You need a HighLevel location (sub-account) with data you want to measure.
Use a user who can authorise the Elevale marketplace app for that location.
Elevale requests read-only scopes: contacts, conversations, opportunities, calendars, locations, and payment transactions/subscriptions.
Pop-ups must be allowed - OAuth opens in the same window for HighLevel providers.
Disconnect and data retention
Disconnect from Workspace Settings → Integrations to revoke stored credentials and stop scheduled syncs.
Previously synced KPI history remains until you delete or convert those KPIs.
Subprocessors and data handling: Subprocessors and integrations