A one-way connection: noombat reads your CRM on a schedule and never writes anything back. One dedicated user, one API token — an admin can complete this in about 15 minutes.
| Organizations | the companies you sell to |
| Persons | the people at those companies |
| Leads | optional — if you use the Leads inbox |
| Deals, pipelines & stages | pipeline and revenue outcomes |
| Activities | calls, meetings, tasks on your records |
| Notes | context logged on deals and contacts |
| Deal- and contact-linked emails | emails shared into the CRM (private inboxes stay private) |
| Users | record owners, for attribution |
A dedicated account keeps noombat's access separate from any person — attributable on its own, unaffected by staff changes, revocable in one click. Heads-up on cost: Pipedrive has no free integration seats, so this user occupies a normal paid seat on your plan.
Company settings > Manage users > Add userintegrations@noombat.ai — we monitor this inbox and complete the account activation ourselves, so nothing lands on your plate.Two dials matter: what the user may do (permission set) and what it may see (visibility group). We want minimal doing and full seeing.
Permission set
On plans with custom permission sets (higher tiers — Premium/Ultimate on current naming), create a set called noombat from the regular-user template and switch off everything Pipedrive lets you switch off:
On plans without custom sets, assign the default regular-user set — the guarantees in the security FAQ below hold either way.
Visibility
Put the user in a visibility group that sees your whole book (the default “entire company” group, if you haven't restricted it). If your org uses restrictive visibility groups, whatever the integration user can't see, noombat can't score — data gaps here are silent, so this is worth 30 seconds of checking.
Why not just read-only?
The token belongs to the integration user, so it must be copied while logged in as that user (from the activation we complete in step 1, or via your admin's log-in-as if your plan has it).
Profile icon > Personal preferences > APICopy the personal API token. Each user has exactly one valid token — generating a new one instantly invalidates the old, which is also your rotation and kill-switch story.
Since the account email is ours, we can also do this step ourselves after activation — in that case just tell us the user is created and assigned, and skip step 4.
yourco.pipedrive.com)Share the token securely — never in a plain email
integrations@noombat.ai. Also good: a self-destructing link (e.g. onetimesecret.com). If the token ever leaks, regenerate it in the user's API tab — the old one dies instantly.Once the details arrive we run a verification the same day — connecting as the integration user and checking each data type returns what it should — and confirm back to you. If anything's off, the table below is the complete list of what it could be.
If yours isn't here, send it over — we diagnose these quickly.
| What you see | Why | Fix |
|---|---|---|
| No “API” tab under Personal preferences | The user's permission set doesn't have API access enabled — admins can switch API access per permission set. | Company settings > Manage users > Permission sets > (the set) > enable API access, then log back in as the integration user. |
| 401 Unauthorized on every request | The token was regenerated (each user has exactly one valid token — a new one kills the old), or the user was deactivated. | Step 3 — copy the current token from the integration user's Personal preferences > API, and re-send it to us. |
| Data arrives, but it's a fraction of your book | Visibility groups: the integration user only sees items its group is allowed to see. | Step 2 — put the integration user in a visibility group that sees everything (or the default “entire company” group). |
| 429 Too Many Requests | Pipedrive meters API usage with a daily token budget (30,000 × plan multiplier × seats, resets every 24h). | Usually nothing — our sync paces itself and backs off automatically. If it persists, another integration may be consuming the budget; we can look at it together. |
| Emails you expected aren't in noombat | Only emails linked/shared to deals and contacts are visible beyond their owner's inbox — Pipedrive keeps private mailboxes private, API included. | Have reps use Smart BCC / email sync with sharing on. This mirrors what your own team can see in Pipedrive. |
The questions security-conscious admins ask us, answered the way we answer them — including the honest parts.
Our sync is strictly one-way: noombat only ever reads, and nothing is written back. Full transparency on the platform side, because it's the honest difference from HubSpot and Salesforce: Pipedrive API tokens can't be scoped, so the token can do whatever the integration user can do — and Pipedrive has no fully read-only user (creation rights can't be switched off). That's why step 2 strips every write permission Pipedrive lets you strip (deleting, exporting, bulk editing, editing others' items), why we use a dedicated user so every API action is attributable to noombat alone, and why record change history would show any modification. If platform-enforced read-only is a hard requirement for you, talk to us — we'll walk through it together.
Organizations, persons and leads (who you sell to), deals (pipeline and revenue), and activity — calls, meetings, notes, shared emails. noombat keeps a scored mirror and uses it to connect the leads it generates to the activity and revenue they produce. Historical data matters: the scoring learns from what already happened, which is why a forward-only feed isn't enough.
One seat, at your plan's per-seat price — unlike Salesforce and HubSpot, Pipedrive has no free integration users, so the dedicated account occupies a normal paid seat. If that's a blocker, the fallback is using an existing admin's token, with the trade-offs that access then rides on that person's account (leaves when they leave, dies if their token is regenerated) and API actions show under their name. We recommend the dedicated seat; happy to talk through the fallback.
Pipedrive gives each company a daily API budget (30,000 tokens × plan multiplier × number of seats). Our sync is scheduled and incremental — after the initial history pull it reads only what changed, and it backs off automatically on 429s, so it's designed to live well within the budget alongside your other integrations.
Instantly, two ways: regenerate the integration user's API token (each user has exactly one valid token, so a new one kills ours immediately), or deactivate the user. Both are your-side actions we can't undo.
In an isolated per-client database schema hosted in the EU (Frankfurt), encrypted in transit and at rest, never mixed with other customers' data, and deleted if we part ways. We're happy to put data-handling terms in writing or walk through it with your security team.
Anything unclear, or a policy conflict? integrations@noombat.ai — or bring your Pipedrive admin and we'll do the whole thing together on a call. Using HubSpot or Salesforce instead? Those guides are just as ready.