- Knowledge Base
- Account & Setup
- Account Security
- Configure AI connector access to Sensitive Data and engagements
Configure AI connector access to Sensitive Data and engagements
Last updated: October 5, 2026
Available with any of the following subscriptions, except where noted:
-
Marketing Hub Enterprise
-
Sales Hub Enterprise
-
Service Hub Enterprise
-
Data Hub Enterprise
-
Content Hub Enterprise
-
Smart CRM Enterprise
-
Revenue Hub Enterprise
If your HubSpot account has Sensitive Data settings turned on, you can allow supported third-party AI connectors to access Sensitive Data. When connecting a third-party AI connector, such as the HubSpot connector for ChatGPT or Claude, you can select optional permissions that provide access to Sensitive Data during installation or reauthentication. This provides read-only access to Sensitive Data based on the permissions granted to the app and the user's permissions.
For example, if sensitive customer information is stored in Sensitive Data properties or engagements, you can allow the AI connector to access that information when generating AI insights or completing AI-powered workflows.
Supported AI connectors include ChatGPT, Claude, Copilot, Gemini, and the Remote MCP server. The Sensitive Data available to each connector varies.
| AI connector | Sensitive Data access |
| ChatGPT | Sensitive Data properties and engagements |
| Claude | Sensitive Data properties and engagements |
| Copilot | Sensitive Data properties and engagements |
| Gemini | Sensitive Data engagements |
| Remote MCP server | Sensitive Data engagements |
Please note: if you're a Super Admin, you can opt your account into the Enable AI Connectors for Sensitive Data Portals beta.
Before you get started
Before you use this feature, review the following requirements and limitations.
Requirements
Permissions required
- Super Admin permissions are required to configure AI connector access to Sensitive Data during installation or reauthorization.
- After Sensitive Data access is configured, users are required to have the relevant CRM object or property-level permissions to access the corresponding data through the AI connector.
Your account must have Sensitive Data settings turned on before you can configure AI connector access to Sensitive Data.
Limitations & considerations
- AI connector access is limited to standard Sensitive Data properties, including properties that contain HIPAA-protected health data, and engagement data. Highly Sensitive Data properties remain restricted.
- After Sensitive Data permissions are turned on, some AI connectors (e.g., the HubSpot connector for Claude) may not return certain CRM properties if the property name is identified as sensitive. This behavior is controlled by the model provider's safety guardrails, not by HubSpot permissions.
Disconnect and reauthenticate the AI connector
If the AI connector is already connected to HubSpot, you’ll need to disconnect the connector from both the AI provider and HubSpot and reauthenticate it before configuring Sensitive Data access. If you’re installing the AI connector for the first time, continue to configure AI connector access to Sensitive Data.
The steps to disconnect and reauthenticate the app vary by AI connector.
To disconnect the AI connector:
- In your AI provider account, select your profile icon or navigate to Settings.
- Click Connectors or Apps.
- Click HubSpot.
- Click Disconnect.
-
In your HubSpot account, click the
settings icon in the top navigation bar. - In the left sidebar menu, navigate to Integrations > Connected Apps.
- Click the name of the app.
- In the upper right, click Actions, then select Uninstall [AI connector].
To reauthenticate the AI connector, follow the setup steps for the AI provider:
- Set up the HubSpot connector for ChatGPT
- Set up the HubSpot connector for Claude
- Connect and use the HubSpot Agent for Copilot
- Set up the HubSpot connector for Gemini
Configure AI connector access to Sensitive Data
After you reauthenticate or install the AI connector, select the optional permissions that provide access to Sensitive Data or engagements.
Please note: AI connectors can request write permissions for engagements (e.g., Create, delete, or make changes to [activities]) in all HubSpot accounts. However, engagements are limited to read-only access in accounts with Sensitive Data. This means that write permissions can be selected when configuring an AI connector, but any attempts to update engagements will be blocked.
The steps to configure access to Sensitive Data vary by AI connector.
-
In your HubSpot account, click the
settings icon in the top navigation bar. - In the left sidebar menu, navigate to Integrations > Connected Apps.
- Click the name of the app.
- In the App access and permissions section, select the following permissions:
- Engagement permissions: view properties and other details about engagements (e.g., calls, emails, meetings, notes, or tasks).
- [Sensitive] property permissions (ChatGPT, Claude, and Copilot only): view properties and other details, including Sensitive Data.
- Complete the app installation or update the app’s permissions.
Please note: after you reconnect the AI connector, new AI connector permissions may take up to two hours to appear in the App access and permissions section.
