Overview
LowerPlane connects to Intercom using an access token from a private app with read-only permissions. Once connected, LowerPlane syncs your Intercom teammates (admins) so they appear in Access Reviews — helping you verify that only current employees have access to customer conversations, and that offboarded employees have been removed.What LowerPlane Collects
| Data | What LowerPlane Collects |
|---|---|
| Teammates (Admins) | Name, email, job title, and whether they hold an inbox seat |
| Access Roles | Inbox seat holders are flagged as support agents for access review scoping |
Step 1: Create a Private App
- Open the Intercom Developer Hub
- Click New app
- Enter a name, for example:
- Select your workspace and choose Internal integration
- Click Create app
You need Intercom admin access to create apps in the Developer Hub.
Step 2: Set Permissions
- In your app, go to Configure → Permissions
- Enable Read admins
- Leave all other permissions disabled — LowerPlane does not need them
- Save the changes
Step 3: Copy the Access Token
- Go to Configure → Authentication
- Copy the Access Token
Step 4: Connect in LowerPlane
- Go to Integrations in LowerPlane
- Find Intercom and click Connect
- Paste the Access Token
- Select your data-hosting Region (US, EU, or AU)
- Click Connect
Your region determines the API endpoint (
api.intercom.io, api.eu.intercom.io, or api.au.intercom.io). If validation fails with a valid token, double-check that the selected region matches your Intercom workspace’s data-hosting region.Automated Checks
When Intercom is connected, LowerPlane automatically:- Includes Intercom teammates in user access reviews for SOC 2 and ISO 27001
- Flags Intercom accounts belonging to offboarded employees so access can be revoked
- Tracks which teammates hold inbox seats (access to customer conversations)