AI connectors need an accountable application lifecycle: approved installation, least privilege, enterprise identity, ownership, and visible activity
Source: HubSpot
HubSpot's Fall 2026 release adds App Governance controls that let administrators decide which apps and AI connectors are allowed, who can install them, and whether an approval is required. New granular OAuth scopes distinguish read from write access, while an optional user-level model constrains an app's runtime action by the permissions of the person using it. The release also adds app ownership and activity logs; for Claude Enterprise, verified-domain restrictions can keep MCP connector access to company-provisioned accounts.
Why this matters: Treat every agent connector as a managed integration, even when it arrives through a familiar SaaS product. Put an accountable owner and approval path behind each installation; grant the smallest data and action scopes; bind runtime actions to a named enterprise identity; and review activity and offboarding effects before access becomes orphaned. MCP makes these controls more urgent, because a conversational interface can otherwise turn a personal identity or broad OAuth grant into durable access to operational data.
Read HubSpot's connected-app governance announcement