ChatGPT's Deep Research and the HubSpot connector, for CRM admins

What the HubSpot connector for ChatGPT can see, which admin decisions cannot be undone, what leaves your CRM, and when it is the wrong tool for the job.

John Kelleher
John Kelleher

Somebody in your business has connected ChatGPT to HubSpot. Possibly a rep who saw a demo, possibly the sales director, possibly an external consultant who holds Super Admin in your portal. You are the person who has to answer what it can see.

The reassuring part is true. The connector runs under the connecting user's own HubSpot permissions, so a rep sees the deals a rep can see. The part people get wrong is what follows from that, and the fact that two of the decisions you make when you install it cannot be reversed.

Two modes, and only one of them can change your data

The HubSpot connector for ChatGPT gives a person two ways to work.

Chat answers everyday questions. How many high-priority tickets came in last week, what has happened on this account since April, which deals in my pipeline have not been touched. It can also create and update records and log activities.

Deep research does something different. It plans a multi-step piece of work, proposes that plan for you to edit, runs for several minutes across the sources you allowed, and returns a structured report with citations. The citations link back to the HubSpot records they came from. OpenAI's documentation is explicit about the boundary: "Deep research only uses read actions from connected apps. It does not use app write actions as part of research." So deep research reads, and only chat writes.

What the connector reaches, per HubSpot's own object table:

AccessObjects
Read, create and updateContacts, companies, deals, tickets, line items, products, and engagements (calls, meetings, notes, tasks, emails)
Read onlyUsers and teams, quotes, invoices, orders, carts, subscriptions, lists, campaigns, landing pages, website pages, blog posts
No accessCustom objects, custom Sensitive Data Properties, sensitive content from Sensitive Data Covered Services

Nothing can be deleted. And if Sensitive Data is turned on in your account, ChatGPT cannot access any engagement data at all, which quietly removes most of the value for the accounts most likely to have it enabled.

The identity that connects is the security boundary

Per-user permissions are enforced, and that is a genuine control rather than marketing. HubSpot states the connector "automatically respects the user permissions defined in HubSpot", down to team-limited contact access.

Two consequences follow, and they are the ones that get missed.

First, whoever connects defines the reach. A Super Admin connecting their own login has given ChatGPT the reach of a Super Admin, because as far as HubSpot is concerned it is them.

Second, HubSpot's own FAQ answers the question most people are too polite to ask. If external agencies or consultants in your portal hold Super Admin, they can connect the connector, and other users can then connect their own logins. The attempt is logged, but logging it is not the same as approving it.

One practical limit worth knowing: a ChatGPT account can be connected to one HubSpot account at a time, so a partner or a group with several portals has to disconnect and reconnect to switch.

Three of the admin controls are one-way doors

This is the part to read before you install, not after. HubSpot documents all of it plainly, and none of it is what an admin expects.

  • Once a Super Admin turns on access for all users, that access cannot be turned off globally again.
  • Users are limited to the permissions the Super Admin selected at install, but once users have connected, the Super Admin cannot revoke those permissions.
  • Uninstalling the connector from the account does not remove user-level access. Each user has to uninstall it themselves.
  • To change the permission set later, you uninstall and reinstall from Connected Apps, and every user who already installed it must uninstall and reinstall too.

So the permission screen during installation is the decision, and everything after it is negotiation. Treat it as a change you schedule rather than a box you click while somebody waits. If you are unsure, grant less: widening later means one reconnection, narrowing later means chasing every user who ever connected.

What you can see afterwards, and what you cannot

On the HubSpot side, you get two things. Create and update actions are attributed in your account's audit log to both the user and the ChatGPT connector, so a change is traceable to a person and to the route it came through. Audit logs also show which users connected or reconnected the connector, and when.

What HubSpot does not show you is what anyone asked. The questions, the answers and any report produced live in ChatGPT, and your visibility there depends entirely on the ChatGPT plan your people are on.

ChatGPT BusinessChatGPT Enterprise and Edu
Apps and pluginsEnabled by default, admins manage in workspace settingsDisabled by default until an admin enables them
Access by roleNot availableRole-based access control
What an app may doApp-level enable or disableAction control: all actions, read actions only, or a custom set, plus a rule for actions added later
When ChatGPT asks firstApp permissionsApp permissions, including Always ask and Important actions
Conversation and app-call logsNot availableCompliance Platform logs cover conversations and app calls

The Enterprise row that matters most for a CRM connector is Action control. It lets an admin allow read actions only, at the ChatGPT end, regardless of what the HubSpot install granted. On Business you do not have that, so the HubSpot permission screen is your only scoping mechanism. The wider tier split is covered in the ChatGPT Business and Enterprise governance gap.

A naming note that will save you ten minutes. OpenAI renamed connectors to apps in December 2025, and in July 2026 moved its app directory into a Plugin directory. HubSpot still ships the "HubSpot connector for ChatGPT", and its FAQ confirms the HubSpot App and the HubSpot Connector are the same thing. If the setting is not where the documentation says, that is why.

What actually leaves the CRM

The question goes from ChatGPT to HubSpot, requests route through your account's data centre (an EU-hosted account is routed through the EU data centre), and the records that come back become part of the conversation.

That last clause is the exposure. The conversation is now a copy of CRM data in a second system, with a different retention period and a different administrator. Deleting a contact in HubSpot does not reach a deep research report sitting in somebody's chat history, or the Word file they exported it to, or the slide they pasted it into. This is not exotic. It is what happens every time somebody exports to a spreadsheet, except that nobody thinks of a chat as an export, so nobody counts it in the record of processing. Count it.

On training, the answer is set by the plan, not by anything you configure in HubSpot. OpenAI states that for Business, Enterprise and Edu customers it does not use information accessed from apps to train its models. HubSpot's documentation says that on the consumer plans (Free, Go, Pro, Plus) a user can opt out, and if they do not, OpenAI may use connector data to improve connector performance such as tool use and retrieval accuracy, though not for general model training. If part of your team is connecting on personal paid accounts, that is your answer, and it is a reason to standardise the plan before you standardise the prompts.

HubSpot collects something too, which almost nobody realises: when its MCP server is used, HubSpot may collect summaries of tool calls including the intent of the request and whether it succeeded, with steps taken to anonymise the names of people, companies and deals.

Three things that go wrong on writes

Your validation rules are not in the path. HubSpot states that custom validation rules, including pipeline-stage validations and association-label validations, are not applied when records are created or updated through the connector. The guardrails you built in the CRM do not fire.

Bulk is capped at ten. Create and update actions handle a maximum of ten records per request, so anything larger is a job for an import or a workflow.

Approval is only a control if somebody reads it. Set Write tools to Needs Approval rather than Always allow, then make sure the reviewing habit survives the second week. A language model asked for a deal amount will happily answer "around £40,000, pending confirmation", which is a reasonable sentence and a broken currency field.

When this is the right tool, and when it is a person doing a scheduled job by hand

It earns its place on one-off, judgement-shaped questions where a human reads the answer and decides something. Why did we lose these eleven deals. What do these forty support tickets have in common. What is the history on this account before Thursday's meeting. Analysis nobody would commission a report for, done in ten minutes instead of a day.

The tell that you have the wrong tool is repetition. If somebody runs the same deep research every Monday, they have found a report, a workflow or an agent that should exist and does not, and they are paying for it in their own time. If the output has to land back in a CRM field on a schedule, or be identical each run and provable afterwards, a person in a chat window is the wrong mechanism entirely. The routes for that, including the ones that need no engineering at all, are in connecting an OpenAI agent to HubSpot. Before any of them, check whether a HubSpot report or HubSpot's own AI already does it.

The decision in front of you

Four things, and none of them take long.

  1. Check whether the connector is already installed, who installed it, and which permissions were selected. The audit log tells you who has connected and when.
  2. Decide the scope now, while changing it is still cheap. Read-only is a legitimate answer, and for most of the value it is the right one.
  3. Find out which ChatGPT plans your people are on, because that determines the training position and whether you have any logging at all.
  4. Add the chat history to your list of places CRM data lives, and say so in your record of processing.

We are a HubSpot Diamond Solutions Partner and an OpenAI Select Partner, which is why we can speak to both halves of this rather than one. We resell nothing, take no margin on your usage, and will tell you when the answer is a HubSpot report and no new software at all. If the exposure you are worried about points the other way, at queries leaving your business rather than a tool reaching into it, that is a different problem: see is ChatGPT's browsing safe for confidential research?

If you are earlier than this and still weighing the options, start with what ChatGPT and the OpenAI API actually do for a UK business.

If you want the scoping decision made properly the first time, request a quote.

John Kelleher

John Kelleher

Author
John is the founder and the Chief Executive at SpotDev.

Stay Updated with Our Latest Insights

Get expert HubSpot tips and integration strategies delivered to your inbox.