HubSpot joins as a CRM the agent can read and write, with contacts held behind a rule rather than a setting
HubSpot closes the loop between ad spend and what the pipeline did with it: deal attribution, contact source breakdown, campaign spend lines and form submissions, next to the platforms that produced them. It is also the integration where the personal-data question is sharpest, so that rule is stated rather than buried.
Personal data is a rule, not a toggle
A CRM is made of people. Reading identified contacts is allowed only on an interactive task a person started, whose goal actually asks for those fields. It is refused over MCP, refused on the autonomous loop, refused on scheduled and email-started tasks, and refused on dashboard replays.
An allowed lookup is never cached and never paged past twenty rows. Everything that leaves the app goes through one redaction table — the approval mail, the magic-link approval page and the digests all read it, while the task page keeps the exact values for the person who asked.
What shipped
- 17 reads, 31 writes. Contacts, companies, deals, lists, campaigns with budget and spend lines, forms, landing pages and owners.
- Every write needs an opt-in scope. A portal is always connectable read-only; the write scopes are optional ones an operator adds and a re-authorization grants — so nobody gets write access by accident.
- Creates never activate. A campaign lands planned or paused, a deal in an open stage, a list empty and static, a task not-started, a file private, a landing page as a draft.
- Money is bookkeeping only. Budget and spend lines and a deal's own money properties, each capped — nothing here moves money, and marketing-contact status is refused on every lane because HubSpot bills per marketing contact.
Frequently asked questions
- Can the agent read my HubSpot contacts?
- Only on an interactive task you started whose goal asks for those fields. It is refused over MCP, on the autonomous loop, on scheduled and email-started tasks and on dashboard replays; an allowed lookup is never cached and never pages past twenty rows.
- Does connecting HubSpot give the agent write access?
- No. A portal is always connectable read-only, and the write scopes are optional ones an operator has to add followed by a re-authorization. Nobody gets writes by default.
- Will it change a deal stage or an owner automatically?
- No. Stage changes, owner changes and lead-status changes are person-class on every lane, as are all deletes, contact writes, list membership and publishing a landing page.
- Can it move money in HubSpot?
- No. Money is bookkeeping only — budget and spend lines and a deal's own money properties, each capped. Marketing-contact status, consent properties and every money movement are refused on every lane.