Overview

LowerPlane connects to Intercom using an access token from a private app with read-only permissions. Once connected, LowerPlane syncs your Intercom teammates (admins) so they appear in Access Reviews — helping you verify that only current employees have access to customer conversations, and that offboarded employees have been removed.

What LowerPlane Collects

DataWhat LowerPlane Collects
Teammates (Admins)Name, email, job title, and whether they hold an inbox seat
Access RolesInbox seat holders are flagged as support agents for access review scoping
LowerPlane only reads teammate data. It never reads customer conversations, contacts, or messages.

Step 1: Create a Private App

  1. Open the Intercom Developer Hub
  2. Click New app
  3. Enter a name, for example:
lowerplane-access-review
  1. Select your workspace and choose Internal integration
  2. Click Create app
You need Intercom admin access to create apps in the Developer Hub.

Step 2: Set Permissions

  1. In your app, go to Configure → Permissions
  2. Enable Read admins
  3. Leave all other permissions disabled — LowerPlane does not need them
  4. Save the changes

Step 3: Copy the Access Token

  1. Go to Configure → Authentication
  2. Copy the Access Token
Important: Treat this token like a password. Anyone with the token can read data allowed by the app’s permissions.

Step 4: Connect in LowerPlane

  1. Go to Integrations in LowerPlane
  2. Find Intercom and click Connect
  3. Paste the Access Token
  4. Select your data-hosting Region (US, EU, or AU)
  5. Click Connect
LowerPlane validates the token and starts the first sync automatically.
Your region determines the API endpoint (api.intercom.io, api.eu.intercom.io, or api.au.intercom.io). If validation fails with a valid token, double-check that the selected region matches your Intercom workspace’s data-hosting region.

Automated Checks

When Intercom is connected, LowerPlane automatically:
  • Includes Intercom teammates in user access reviews for SOC 2 and ISO 27001
  • Flags Intercom accounts belonging to offboarded employees so access can be revoked
  • Tracks which teammates hold inbox seats (access to customer conversations)