AI connectors and HubSpot permissions: governance and best practice
Understand how HubSpot AI connectors work, what permissions they can request, and what your organisation should consider before approving access.
AI platforms can increasingly connect directly to HubSpot, allowing users to bring CRM context into the AI tools they already use.
Depending on the connector and permissions available, this can range from searching and analysing CRM information to creating or updating records and logging activities. HubSpot currently provides connectors for ChatGPT, Claude and Gemini, alongside MCP capabilities for compatible AI tools.
As these capabilities develop, administrators may be asked to approve new connectors, enable additional functionality or grant expanded permissions.
The availability of a connector or permission does not necessarily mean that your organisation should enable it. Each request should be considered as part of your wider security, data-protection and AI governance processes.
This article explains how HubSpot AI connectors work, what connector permissions mean, what to consider before approving them and where Forbidden can help.
What is an AI connector?An AI connector allows an AI platform to interact with another business system, such as HubSpot.
This can allow the AI tool to retrieve relevant information from that system and, where supported and authorised, perform actions within it.
Depending on the platforms your organisation uses, AI tools may connect with systems such as:
- CRM platforms.
- Email and calendars.
- Document and file-storage platforms.
- Collaboration tools.
- Project-management systems.
- Finance and operational systems.
- Other business applications.
The terminology used by different vendors varies. You may see these connections described as connectors, integrations, apps or MCP connections.
Although the underlying technology may differ, the key governance question remains the same:
What information and functionality are we allowing this AI tool to access?
Which AI connectors are available for HubSpot?HubSpot currently provides AI connectors that bring HubSpot customer context into tools including ChatGPT, Claude and Gemini. HubSpot also provides a hosted Model Context Protocol (MCP) server that can connect HubSpot with compatible AI tools and agents.
The capabilities of these connections are not necessarily identical. Some may focus on retrieving and analysing CRM information, while others can support actions that write information back to HubSpot.
View HubSpot's AI connectors overview
HubSpot connector for ChatGPTThe HubSpot connector for ChatGPT allows users to bring HubSpot CRM context into ChatGPT for everyday questions and deeper analysis.
HubSpot currently describes two main uses: chat for quick CRM questions and deep research for more detailed analysis. The connector can access core CRM objects including contacts, companies, deals and tickets, together with relevant properties and associations.
HubSpot's wider AI connector documentation also describes supported light actions for creating and updating CRM records and logging activities.
As with any AI connector, organisations should review the current functionality and permissions before approving it for use.
Learn more about the HubSpot connector for ChatGPT
HubSpot connector for ClaudeThe HubSpot connector for Claude brings HubSpot CRM context into Claude so users can analyse customer information and generate insights.
HubSpot's current documentation describes capabilities including CRM analysis and supported actions in HubSpot. The precise functionality available can depend on the connector configuration and permissions in place.
Because connectors continue to develop, administrators may periodically encounter new functionality or permissions that require review.
The availability of those capabilities does not mean that your organisation is required to approve them.
Learn more about the HubSpot connector for Claude
HubSpot connector for GeminiHubSpot also provides a connector for Google's Gemini.
HubSpot describes the connector as allowing users to bring HubSpot context into Gemini, retrieve information such as contacts, deals and companies, and use that context to support tasks such as drafting follow-up emails and notes.
As with the other connectors, organisations should review the current functionality and permissions rather than assuming its access is identical to another AI platform.
Learn more about the HubSpot connector for Gemini
What about other AI tools?HubSpot is not limited to named AI connectors.
HubSpot also provides a hosted Model Context Protocol (MCP) server. MCP provides a standardised way for compatible AI tools and agents to request information from external systems such as HubSpot.
HubSpot's remote MCP server can provide permission-aware read and write access to CRM information for compatible AI tools and agents.
This means organisations may increasingly be able to connect HubSpot with:
- Custom AI agents.
- Third-party AI platforms.
- Internal AI applications.
- Other MCP-compatible tools.
AI connector governance should therefore consider both the connectors available today and how access may expand as your organisation adopts other AI tools.
Learn more about HubSpot's MCP server
Are all HubSpot AI connectors the same?No.
The capabilities of each connector can differ significantly and can change as HubSpot and the relevant AI provider develop their integration.
Depending on the connector, an AI tool may be able to:
- Search or retrieve CRM information.
- Analyse CRM data.
- Access supported CRM objects and activities.
- Create CRM records.
- Update existing records.
- Log activities.
- Perform other supported HubSpot actions.
You should therefore assess the specific connector and permissions being requested, rather than assuming that approval of one AI connector means another has equivalent access.
What do connector permissions control?Permissions help determine what a connected application can access or do within HubSpot.
HubSpot allows administrators to review the data and APIs an approved app can access. Where an app has optional data permissions, those permissions can be enabled or restricted separately from the permissions that are required for the app to operate.
Depending on the connector, permissions may relate to actions such as:
- Reading or searching CRM data.
- Accessing particular CRM objects.
- Creating records.
- Updating information.
- Logging activities.
- Using other supported HubSpot functionality.
A request for an additional permission can therefore represent a material change in what the connected application is able to access or do.
The availability of a permission does not mean that your organisation is required to approve it.
What happens when a connector introduces a new permission?Connectors evolve over time.
An application that originally required limited access may later introduce new capabilities or request additional permissions.
When this happens, the new permission should be considered as a change to system access.
Its availability should not automatically be interpreted as:
- A recommendation that you enable it.
- Confirmation that your organisation needs it.
- Confirmation that it meets your internal security requirements.
- Approval from your Information Security or Data Protection teams.
- Confirmation that it is appropriate for your organisation's risk profile.
Instead, understand what the new permission enables and assess whether there is a legitimate business requirement for it.
What controls does HubSpot provide?HubSpot provides administrative controls for managing connected applications.
Super Admins can review and approve apps, control which users or teams may install them, review required and optional data permissions, and revoke previous approval.
HubSpot's Connected Apps area also provides information about installed applications, their access and permissions, connection status and supported application activity.
These controls can help organisations manage how applications interact with HubSpot, but they are only one part of managing AI access appropriately.
Learn more about managing access to apps in HubSpot
Learn more about managing connected apps
Platform controls are not the same as organisational approvalThe availability of a connector within HubSpot should not be treated as confirmation that it is suitable for your organisation.
Similarly, HubSpot providing a connector or technical control does not replace your organisation's responsibility to assess matters such as:
- Information security.
- Data protection.
- Regulatory obligations.
- Internal policies.
- AI governance.
- Supplier due diligence.
- Contractual requirements.
- Organisational risk.
The decision to approve a connector ultimately sits with your organisation.
Consider the combined access across your systemsAI connector governance should not be considered solely as a HubSpot issue.
The same AI platform may be connected to several systems across your organisation.
For example, an AI platform could potentially have access to:
- HubSpot CRM.
- Email.
- Calendars.
- Documents and files.
- Internal knowledge.
- Collaboration tools.
- Project-management platforms.
- Other operational applications.
Each connection may appear reasonable when considered individually. However, the combined access available to the AI platform may be considerably broader.
Your governance process should therefore consider both the permissions associated with an individual HubSpot connector and the overall access granted to the AI platform across your technology environment.
Establish an internal AI connector policyA documented process for approving and managing AI connectors can help your organisation assess requests consistently.
Your policy could define:
- Who may approve a new connector.
- Who reviews new or expanded permissions.
- What business justification is required.
- Which systems AI tools are permitted to access.
- Which types of data may be accessed.
- When read access is acceptable.
- When create, update or delete access is acceptable.
- Whether IT, Information Security, Legal or Data Protection approval is required.
- How access is restricted by user, team and role.
- How approvals and decisions are documented.
- How frequently connectors and permissions are reviewed.
- When access should be withdrawn.
This provides a consistent framework for considering new capabilities rather than treating each permission request in isolation.
Apply the principle of least privilegeAI connectors should only receive the access required to perform an approved business function.
For example, if an AI tool only needs to analyse information from HubSpot, consider whether it genuinely requires permissions that allow information to be created or updated.
Similarly, additional permissions should not necessarily be enabled simply because they might become useful in future.
Where possible:
Start with the minimum appropriate access and expand it when there is a defined and approved requirement.
What should we consider before approving a permission?Before enabling a new connector or expanding an existing connector's access, consider the following questions.
What does the permission enable?
Understand which HubSpot records, information or functionality the permission relates to.
Why is it required?
Identify the business requirement for providing the additional access.
Who will use it?
Consider which users, teams or roles require the capability.
What information can it access?
Consider both the volume and sensitivity of the information that could become available through the connector.
What can it change?
Understand whether the permission allows the connector to:
- Read information.
- Create information.
- Update information.
- Delete information.
Write and delete access generally requires different consideration from read-only access because the connected tool may be able to make changes within your CRM.
Could less access achieve the same result?
Consider whether a lower level of permission would still meet the business requirement.
Who should approve it?
Depending on your organisation, approval may involve stakeholders such as:
- IT.
- Information Security.
- Data Protection.
- Legal.
- Compliance.
- System owners.
- Business owners.
Connector approval should not be treated as a one-off exercise.
AI platforms and integrations can develop quickly. A connector originally approved for a limited purpose may later gain new capabilities or request additional permissions.
Organisations should therefore periodically review:
- Which AI platforms are authorised.
- Which connectors are enabled.
- Which users can access them.
- Which systems can be accessed.
- Which permissions have been granted.
- Whether those permissions are still required.
- Whether the original business justification still applies.
Where access is no longer required, it should be removed or restricted using the controls available to your organisation.
What should we do when we receive a new permission request?When an AI connector requests additional HubSpot permissions:
- Do not approve the permission automatically.
- Identify exactly what the permission enables.
- Confirm whether there is an approved business requirement.
- Understand which data and HubSpot functionality it affects.
- Determine whether the access is read, create, update or delete.
- Consider whether a lower level of access would be sufficient.
- Complete any required internal security, legal or data-protection review.
- Document the decision.
- Review the permission periodically after approval.
If there is no current requirement for an optional permission, leaving it disabled can help avoid granting unnecessary access.
What can Forbidden help with?Forbidden can help you understand the HubSpot-specific implications of an AI connector or permission.
For example, we can help explain:
- What a particular HubSpot permission relates to.
- Which HubSpot objects or functionality it may affect.
- Whether the connector supports read or write capabilities.
- What relevant HubSpot administration controls are available.
- How HubSpot permissions and access could be structured appropriately.
- What changes may occur within your HubSpot portal when supported actions are used.
However, Forbidden does not determine whether an AI platform or third-party service is suitable for your wider organisation.
Security assessments, data-protection assessments, supplier due diligence, legal reviews and organisational risk acceptance should be managed through your own internal governance processes using the documentation supplied by the relevant vendors.
Forbidden cannot approve a third-party AI platform or connector, or accept the associated organisational risk on your behalf.
Further informationAI connector functionality is developing quickly. Always review current vendor documentation when considering a new connector or permission.
Useful HubSpot resources include:
- HubSpot AI connectors overview
- HubSpot connector for ChatGPT
- HubSpot connector for Claude
- HubSpot connector for Gemini
- HubSpot MCP server
- Manage access to apps in HubSpot
- Manage connected apps in HubSpot
You should also review the security, privacy, data-processing and connector documentation supplied by the relevant AI provider before approving access.