Overview
LowerPlane connects to Notion using an internal integration token with read-only access. Once connected, LowerPlane syncs your Notion workspace members so they appear in Access Reviews — helping you verify that only current employees have access to your workspace, and that offboarded employees have been removed.What LowerPlane Collects
| Data | What LowerPlane Collects |
|---|---|
| Workspace members | Name and email of each person in the workspace |
| Access status | Whether each member maps to a current employee (for offboarding) |
GET /v1/users). It never reads your pages, databases, or content.
Prerequisites
You must be a workspace owner to create a connection.Step 1: Create an Internal Connection
Notion manages API connections under Settings → Connections (also reachable via Developer tools → Connections).- In Notion, open Settings → Connections
- Click + New connection
- Enter a name, for example:
- Under Installable in, select your workspace
- Set Auth type to Access token (this is an internal connection with a static token — not OAuth)
- Create the connection
Step 2: Enable the “Read user info (including email)” Capability
- Open the connection’s settings
- Under User Capabilities, select Read user info (including email)
- Save the changes
Without this capability, Notion returns member names but not emails — and LowerPlane needs emails to match members to your employee records for offboarding checks. The other options, Read user info (not including user’s email address) and No user information, leave emails blank.
Step 3: Copy the Integration Token
- Back on the Connections list, click the ••• menu next to your connection
- Choose Retrieve an internal API token (Notion also calls this the internal connection token)
- Copy the token (it starts with
ntn_)
Step 4: Connect in LowerPlane
- Go to Integrations in LowerPlane
- Find Notion and click Connect
- Paste the Integration Token
- Click Connect
Automated Checks
When Notion is connected, LowerPlane automatically:- Includes Notion members in user access reviews for SOC 2 (CC6.1/CC6.2) and ISO 27001 (A.5.16/A.5.18)
- Flags Notion accounts belonging to offboarded employees so access can be revoked
- Confirms every account is traceable to a named individual