On 16 Sep 2026 Anthropic merged Claude Cowork and Claude chat into a single product. There is no longer a separate place to go when you want Claude to do work rather than answer a question: a person asks, and Claude decides whether the request needs a reply or a task. It is rolling out to Pro and Max plans now, Team and Free plans follow "soon", and Enterprise admins get at least 30 days' notice before anything changes.
If your business runs on HubSpot and some of your staff pay for Claude, this matters for one specific reason. HubSpot's own connector for Claude, which launched read-only in July 2025 and gained write access later that year, was updated again on 17 Sep 2026, the day after the merge. It gives Claude read and write access to most of a HubSpot portal. Until last week, using that access for an actual task meant deliberately opening Cowork. From now on it is available in any conversation. This post covers what that combination can do, what it cannot, and what a HubSpot admin should check before the rollout reaches their organisation. For the general governance argument, read the companion piece on what the Claude Cowork merge means for your AI policy.
What the HubSpot connector for Claude can reach
These facts are from HubSpot's knowledge base article on the connector, last updated 17 Sep 2026. Older third-party guides, some from late 2025, still describe the connector as read-only, so check the current scope before relying on them.
- It works on every HubSpot tier, including Free, and needs a paid Claude plan: Pro, Max, Team or Enterprise.
- A Super Admin, or a user with App Marketplace access, can connect it without approval. Everyone else needs a Super Admin to approve the connector first, and during approval the Super Admin chooses which data permissions it may have and who in the account may install it. That approval step is your first control point.
- Claude can read contacts, leads, companies, deals, tickets, custom objects, quotes, invoices, pipelines, properties, campaigns, marketing emails, landing pages, calls, meetings, notes, tasks, emails and conversations, among others.
- Claude can create and update contacts, leads, companies, deals, tickets, custom objects, line items, quotes, pipelines, products, landing pages, website pages, blog posts, marketing emails, calls, meetings, notes, tasks and emails. It can create new properties but not edit existing ones. Bulk operations are limited to ten records at a time.
- Claude cannot delete anything through the connector.
- The connector "automatically respects the user permissions defined in HubSpot". A person using Claude sees and changes only what their own HubSpot user can see and change.
- Every create and update made through the connector is recorded in HubSpot's Audit Log, attributed to both the user and the Claude connector, and the Audit Log also records who connected or reconnected it and when.
- Conditional property rules and pipeline stage validation rules are applied on updates. Association label validations are not. If Sensitive Data is enabled in the portal, Claude cannot access engagement data, and the connector never reads custom Sensitive Data properties whether or not that setting is on.
Two things stand out from that list. The write scope is wide, and it includes marketing assets, not only CRM records. And the permission model is the HubSpot user's own permission set, which means the quality of your HubSpot permissions is now the quality of your AI permissions.
What changed on 16 Sep, in HubSpot terms
Before the merge, a person who wanted Claude to update twenty deal records opened Cowork and ran a task. Everyone in the room understood that a task was being run. After the merge, the same person asks a question about their pipeline in an ordinary chat, Claude proposes to fix the stage on the deals it found, and the person clicks approve. The work is the same. The moment of decision has moved from "shall I run a task" to "shall I accept this suggestion", and the second is a much easier click.
By default Claude still asks before each action, and the person approves each one. That default is sound. But a person can switch a conversation to an automatic mode, in which Claude "keeps working without stopping to ask about each step" while automated safety checks run before each action. And longer tasks now continue in Anthropic's cloud after the laptop is closed. Combine those two with a connector that can write to deals, tickets and marketing emails, and you have a workflow that can change a live portal while nobody is looking at it. This is a capability that has arrived faster than most HubSpot permission models were designed for.
Five things a HubSpot admin should check now
Before the unified Claude experience reaches your team:
- Who has connected Claude to your portal, and what it has done. Go to the connected apps list and see whether the HubSpot connector for Claude is installed, and by whom. Then open the Audit Log: it records every connection and every create or update made through the connector, attributed to both the person and the connector. That is your check for what it has actually done, not only who has access. If non-admins have asked for approval, decide the rule before you approve the next one.
- Whether your HubSpot permission sets were written for people or for agents. A sales rep with edit rights across all deals was a reasonable decision when a human was the slowest part of the process. The same rights, exercised by an agent that can update ten records per call, deserve a second look. HubSpot's permission sets and team-based record access are the tools; the connector will honour whatever they say.
- Which validation you are relying on. Pipeline stage rules and conditional property logic will hold. Association label rules will not. A deal cannot be moved to a stage your pipeline forbids, but it can be associated with the wrong company without a check. If a workflow depends on a label being set correctly, it needs a check that does not rely on the person entering the data.
- Whether Sensitive Data is on, and what that costs you. Enabling it removes engagement data from Claude's reach, which may be exactly what a regulated business wants, and may also remove the call and email history that made the connector useful for sales coaching. Decide deliberately.
- Which side you govern from. HubSpot controls what the connected user may touch. Claude's Team and Enterprise settings control whether members may use automatic approval, whether "Always allow" is available for connector tools (off by default), whether cloud execution is enabled (off by default on Enterprise, granted by custom role), and whether sessions are captured in the Compliance API. Claude Enterprise admins can also restrict the connector to company-provisioned accounts. Both sides need an owner, and they should be talking to each other.
This is not the same as HubSpot's own agents
It is worth being precise here, because the two get conflated. Agent Hub is HubSpot's home for the agents it builds and runs inside the platform, with five pre-built agents: prospecting, data, deal progression, customer and AEO. They run under HubSpot's own controls, gated by Hub tier and HubSpot Credits, and they are governed in HubSpot. The distinction is not the model underneath: HubSpot's own AI model cards show its agents running on Claude models alongside models from OpenAI and Google.
A person's Claude session with the HubSpot connector is a different thing. It is a general-purpose agent, run by Anthropic, acting in your portal as that person, and governed partly in Claude's organisation settings and partly by that person's HubSpot permissions. It can do things Agent Hub's agents are not built for, such as reconciling a spreadsheet against your deals or drafting twenty personalised emails from call notes. Neither is better. They answer different questions, and a HubSpot business that wants both automation and accountability will end up using both. What it should not do is govern one and forget the other.
What this looks like done well
The businesses that get value from this quickly will be the ones that treat it as a permissions project first and an AI project second. That means one named owner for the HubSpot side and one for the Claude side, a written list of which objects an agent may read, write and send from, a rule for who may use automatic approval, and a small pilot team on cloud execution before the organisation. A practical split to start from: let the agent summarise, enrich and tag; keep a person on deal-stage moves, lifecycle changes and anything that sends to a customer. Our guide to Claude connectors explains what each connection exposes, and our post on what a personal AI agent should be allowed to touch in your CRM sets out the object-by-object method.
SpotDev is a HubSpot Diamond partner and a Claude Registered Partner, and we build on both. If you want the permission model reviewed before the unified experience reaches your team, start with our diagnostics or read how we approach AI inside HubSpot.
Frequently asked questions
Can Claude change records in my HubSpot portal?
Yes, through the HubSpot connector for Claude. It can create and update contacts, companies, deals, tickets, notes, tasks, emails, marketing emails and pages, among other objects, up to ten records per bulk operation. It cannot delete records. It acts with the connecting user's own HubSpot permissions, and every write is recorded in HubSpot's Audit Log.
Does the Claude connector bypass HubSpot permissions?
No. HubSpot states that the connector automatically respects the user permissions defined in HubSpot. A person using Claude can only see and change what their HubSpot user can see and change.
What changed for HubSpot users when Cowork and chat merged?
Agentic work, including writing to HubSpot through the connector, is now available from any Claude conversation rather than from a separate Cowork surface. Claude still asks before each action by default, but the step of deliberately opening a task tool has gone.
Is Claude with the HubSpot connector the same as HubSpot Agent Hub?
No. Agent Hub is HubSpot's own set of agents running inside the platform under HubSpot's controls. A Claude session with the connector is a general-purpose agent run by Anthropic, acting in the portal as the connected user. They are governed in different places.
What should a HubSpot admin do before the unified Claude experience reaches their team?
Check who has connected Claude and what the Audit Log shows it has done, review permission sets with agents in mind, know which validation rules the connector honours, decide on Sensitive Data, and agree with whoever administers Claude what the approval and cloud-execution settings will be.
Sources
- HubSpot Knowledge Base, "Set up and use the HubSpot connector for Claude", updated 17 Sep 2026. https://knowledge.hubspot.com/integrations/set-up-and-use-the-hubspot-connector-for-claude
- HubSpot Developer Changelog, "Introducing the HubSpot Connector for Claude", 29 Jul 2025. https://developers.hubspot.com/changelog/hubspot-connector-for-claude
- Anthropic, "Claude Cowork and chat are now one Claude", 16 Sep 2026. https://claude.com/blog/cowork-is-now-claude
- Claude Help Centre, "Claude Cowork and chat are one Claude". https://support.claude.com/en/articles/16761823-claude-cowork-and-chat-are-one-claude
- Claude Help Centre, "Use Claude Cowork on Team and Enterprise plans". https://support.claude.com/en/articles/13455879-use-claude-cowork-on-team-and-enterprise-plans
- HubSpot Knowledge Base, "Understand Agent Hub". https://knowledge.hubspot.com/ai/understand-agent-hub
- HubSpot Trust Center, AI model cards. https://trust.hubspot.com/ai
Stay Updated with Our Latest Insights
Get expert HubSpot tips and integration strategies delivered to your inbox.



