19 June 2026

Who gets to tap your CRM data? MCP and AI-connector governance in HubSpot

Most of the Spring 2026 Spotlight coverage went to AI agents. The quieter, more consequential part for RevOps is in the developer changelog: AI agents can now read and write your CRM data through a standard protocol — and the tools to govern that access are still in beta. That ordering matters.

A note up front: availability and scope depend on hub and tier, and beta features change. Verify in your own account.

What shipped

  • HubSpot MCP Server (remote) is now generally available (GA). It gives agents read access to campaigns, landing pages, website pages and blog posts, and write access to CRM objects (HubSpot Developer Changelog).
  • MCP Auth Apps — a self-service tool for building AI connectors to the MCP Server with OAuth 2.1 credential management — is in public beta.
  • App Install Governance Tool — admin controls for approving apps, managing user access and customizing data permissions, including AI connectors — is in public beta.

Why it matters for RevOps

"MCP" sounds like a developer topic. It isn't, the moment an agent can write to your deals, contacts and companies. Then "who connected which AI tool, with what scopes, to which objects?" becomes a data-governance question — and data governance is squarely RevOps territory. This is exactly where the next wave of CRM chaos comes from: not a bad import, but three different AI connectors quietly writing to the same fields with no owner and no policy.

The uncomfortable detail is the sequencing: the write-capable server is GA, while the tools to govern installs and connector auth are still public beta. So the capability to create mess is fully available before the guardrails are finished.

What to watch

  • Write your policy now, not after. Decide which AI connectors are allowed, who approves them, and which objects/fields they may write — before someone connects one "just to try."
  • Treat beta as beta. MCP Auth Apps and the App Install Governance Tool can change; pilot them, don't bet a compliance process on their current shape.
  • Audit scopes, not just installs. Read access to content is low-risk; write access to CRM objects is not. Review what each connector can actually change.

My take

This is genuinely useful — a standard way to let AI act on CRM data is overdue. But it shifts work onto RevOps: you now own a connector inventory and an approval policy the same way you own properties and lifecycle stages. Set that up while you have two connectors, not twenty. The teams that treat AI-connector governance as part of their data model will avoid a cleanup project later.

If you want help defining a connector-governance policy that fits your account, let's talk for 30 minutes. Related: RevOps for Startups and HubSpot Migration.


HubSpot is a trademark of HubSpot, Inc. This post is independent and is not sponsored or endorsed by HubSpot; I am not a certified HubSpot partner. As of June 19, 2026. Availability and beta status can change and vary by hub and tier — check the linked HubSpot source.

Source:  HubSpot Spring 2026 Spotlight — Developer Changelog

← All posts

Related services

Migration

HubSpot Migration

From Salesforce, Pipedrive or Excel to HubSpot — structured, clean, without disruption.

RevOps

RevOps for Startups

Marketing, Sales and Service on one data foundation — for reliable reporting and scalable growth.

B2B SaaS

HubSpot for B2B SaaS

PQL scoring, trial flows, churn signals — HubSpot as a growth engine for software companies.